Show filters
250 Total Results
Displaying 161-170 of 250
Sort by:
Attacker Value
Unknown

CVE-2005-4560

Disclosure Date: December 28, 2005 (last updated February 22, 2025)
The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.
0
Attacker Value
Unknown

CVE-2005-3981

Disclosure Date: December 04, 2005 (last updated February 22, 2025)
NOTE: this issue has been disputed by third parties. Microsoft Windows XP, 2000, and 2003 allows local users to kill a writable process by using the CreateRemoteThread function with certain arguments on a process that has been opened using the OpenProcess function, possibly involving an invalid address for the start routine. NOTE: followup posts have disputed this issue, saying that if a user already has privileges to write to a process, then other functions could be called or the process could be terminated using PROCESS_TERMINATE
0
Attacker Value
Unknown

CVE-2005-3945

Disclosure Date: December 01, 2005 (last updated February 22, 2025)
The SynAttackProtect protection in Microsoft Windows 2003 before SP1 and Windows 2000 before SP4 with Update Roll-up uses a hash of predictable data, which allows remote attackers to cause a denial of service (CPU consumption) via a flood of SYN packets that produce identical hash values, which slows down the hash table lookups.
0
Attacker Value
Unknown

CVE-2005-3641

Disclosure Date: November 16, 2005 (last updated February 22, 2025)
Oracle Databases running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication by supplying a valid username.
0
Attacker Value
Unknown

CVE-2005-3316

Disclosure Date: October 27, 2005 (last updated February 22, 2025)
The installation of ON Symantec Discovery 4.5.x and Symantec Discovery 6.0 creates the (1) DiscoveryWeb and (2) DiscoveryRO database accounts with null passwords, which could allow attackers to gain privileges or prevent Discovery from running by setting another password.
0
Attacker Value
Unknown

CVE-2005-3317

Disclosure Date: October 27, 2005 (last updated February 22, 2025)
Multiple stack-based buffer overflows in ZipGenius 5.5.1.468 and 6.0.2.1041, and other versions before 6.0.2.1050, allow remote attackers to execute arbitrary code via (1) a ZIP archive that contains a file with a long filename, which is not properly handled by (a) zipgenius.exe, (b) zg.exe, (c) zgtips.dll, and (d) contmenu.dll; (2) a long original name in a (a) UUE, (b) XXE, or (c) MIM file, which is not properly handled by zipgenius.exe; or (3) an ACE archive with a file with a long filename, which is not properly handled by unacev2.dll.
0
Attacker Value
Unknown

CVE-2005-3204

Disclosure Date: October 14, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Oracle XML DB 9iR2 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP request.
0
Attacker Value
Unknown

CVE-2005-1982

Disclosure Date: August 10, 2005 (last updated February 22, 2025)
Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.
0
Attacker Value
Unknown

CVE-2005-1218

Disclosure Date: August 10, 2005 (last updated February 22, 2025)
The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.
0
Attacker Value
Unknown

CVE-2005-2388

Disclosure Date: July 27, 2005 (last updated February 22, 2025)
Buffer overflow in a certain USB driver, as used on Microsoft Windows, allows attackers to execute arbitrary code.
0