Show filters
250 Total Results
Displaying 171-180 of 250
Sort by:
Attacker Value
Unknown

CVE-2005-2259

Disclosure Date: July 13, 2005 (last updated February 22, 2025)
The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Software, and (4) MakeBid Reverse Auction allows remote attackers to execute arbitrary code via shell metacharacters in the DISPCLOSED parameter.
0
Attacker Value
Unknown

CVE-2005-2223

Disclosure Date: July 12, 2005 (last updated February 22, 2025)
Unknown vulnerability in the SMTP service in MailEnable Standard before 1.9 and Professional before 1.6 allows remote attackers to cause a denial of service (crash) during authentication.
0
Attacker Value
Unknown

CVE-2005-1205

Disclosure Date: June 14, 2005 (last updated February 22, 2025)
The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.
0
Attacker Value
Unknown

CVE-2005-1208

Disclosure Date: June 14, 2005 (last updated February 22, 2025)
Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflow, as demonstrated using a "ms-its:" URL in Internet Explorer.
0
Attacker Value
Unknown

CVE-2005-1212

Disclosure Date: June 14, 2005 (last updated February 22, 2025)
Buffer overflow in Microsoft Step-by-Step Interactive Training (orun32.exe) allows remote attackers to execute arbitrary code via a bookmark link file (.cbo, cbl, or .cbm extension) with a long User field.
0
Attacker Value
Unknown

CVE-2005-1214

Disclosure Date: June 14, 2005 (last updated February 22, 2025)
Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page.
0
Attacker Value
Unknown

CVE-2005-0356

Disclosure Date: May 31, 2005 (last updated February 22, 2025)
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
0
Attacker Value
Unknown

CVE-2005-1649

Disclosure Date: May 18, 2005 (last updated February 22, 2025)
The IPv6 support in Windows XP SP2, 2003 Server SP1, and Longhorn, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, a variant of CVE-2005-0688 and a reoccurrence of the "Land" vulnerability (CVE-1999-0016).
0
Attacker Value
Unknown

CVE-2005-1495

Disclosure Date: May 11, 2005 (last updated February 22, 2025)
Oracle Database 9i and 10g disables Fine Grained Audit (FGA) after the SYS user executes a SELECT statement on an FGA object, which makes it easier for attackers to escape detection.
0
Attacker Value
Unknown

CVE-2005-1496

Disclosure Date: May 11, 2005 (last updated February 22, 2025)
The DBMS_Scheduler in Oracle 10g allows remote attackers with CREATE JOB privileges to gain additional privileges by changing SESSION_USER to the SYS user.
0