Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2005-07-11 CVE-2005-2209 Cleartext Storage of Sensitive Information vulnerability in Capturix Scanshare 1.06
Capturix ScanShare 1.06 build 50 stores sensitive information such as the password in cleartext in capturixss_cfg.ini, which is readable by local users.
local
low complexity
capturix CWE-312
5.5
2005-07-06 CVE-2005-1916 Link Following vulnerability in multiple products
linki.py in ekg 2005-06-05 and earlier allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.
local
low complexity
ekg-project debian CWE-59
5.5
2005-06-29 CVE-2005-2059 Cross-Site Request Forgery (CSRF) vulnerability in Ubbcentral Ubb.Threads
Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to modify settings as another user via a link or IMG tag.
network
low complexity
ubbcentral CWE-352
6.5
2005-06-09 CVE-2005-1947 Cross-Site Request Forgery (CSRF) vulnerability in Invisioncommunity Gallery
Cross-site request forgery (CSRF) vulnerability in Invision Gallery before 1.3.1 allows remote attackers to delete albums and images as another user via a link or IMG tag to the (1) albums or (2) delimg actions.
network
low complexity
invisioncommunity CWE-352
4.3
2005-06-09 CVE-2005-1879 Link Following vulnerability in Lutel Lutelwall
LutelWall 0.97 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget.
local
low complexity
lutel CWE-59
5.5
2005-06-06 CVE-2005-1880 Link Following vulnerability in Everybuddy 0.4.3
everybuddy 0.4.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget.
local
low complexity
everybuddy CWE-59
5.5
2005-05-19 CVE-2005-1674 Cross-Site Request Forgery (CSRF) vulnerability in Helpcenterlive Help Center Live
Cross-Site Request Forgery (CSRF) vulnerability in Help Center Live allows remote attackers to perform actions as the administrator via a link or IMG tag to view.php.
network
low complexity
helpcenterlive CWE-352
6.5
2005-05-02 CVE-2005-1111 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in multiple products
Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.
local
high complexity
gnu debian canonical CWE-367
4.7
2005-05-02 CVE-2005-0824 Link Following vulnerability in Mathopd
The internal_dump function in Mathopd before 1.5p5, and 1.6x before 1.6b6 BETA, when Mathopd is running with the -n option, allows local users to overwrite arbitrary files via a symlink attack on dump files that are triggered by a SIGWINCH signal.
local
low complexity
mathopd CWE-59
5.5
2005-03-25 CVE-2005-0587 Link Following vulnerability in Mozilla
Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the first .LNK file.
network
low complexity
mozilla CWE-59
6.5