Show filters
403 Total Results
Displaying 361-370 of 403
Sort by:
Attacker Value
Unknown
CVE-2005-3841
Disclosure Date: November 26, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in kPlaylist 1.6 (build 400), and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the searchfor search parameter.
0
Attacker Value
Unknown
CVE-2005-3832
Disclosure Date: November 26, 2005 (last updated February 22, 2025)
Stack-based buffer overflow in (1) CxUux60.dll and (2) CxUux60u.dll, as used in SpeedProject products including (a) Squeez 5.0 Build 4285, and (b) SpeedCommander 11.0 Build 4430 and 10.51 Build 4430, allows user-assisted attackers to execute arbitrary code via a ZIP archive containing a long filename.
0
Attacker Value
Unknown
CVE-2005-3831
Disclosure Date: November 26, 2005 (last updated February 22, 2025)
Stack-based buffer overflow in (1) CxZIP60.dll and (2) CxZIP60u.dll, as used in SpeedProject products including (a) ZipStar 5.0 Build 4285, (b) Squeez 5.0 Build 4285, and (c) SpeedCommander 11.0 Build 4430 and 10.51 Build 4430, allows user-assisted attackers to execute arbitrary code via a ZIP archive containing a long filename.
0
Attacker Value
Unknown
CVE-2005-2939
Disclosure Date: November 18, 2005 (last updated February 22, 2025)
Unquoted Windows search path vulnerability in VMWare Workstation 5.0.0 build-13124 might allow local users to gain privileges via a malicious "program.exe" file in the C: folder.
0
Attacker Value
Unknown
CVE-2005-2667
Disclosure Date: August 23, 2005 (last updated February 22, 2025)
Unknown vulnerability in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows attackers to cause a denial of service via unknown vectors, aka the "CAM TCP port vulnerability."
0
Attacker Value
Unknown
CVE-2005-2444
Disclosure Date: August 03, 2005 (last updated February 22, 2025)
Trillian Pro 3.1 build 121, when checking Yahoo e-mail, stores the password in plaintext in a world readable file and does not delete the file after login, which allows local users to obtain sensitive information.
0
Attacker Value
Unknown
CVE-2005-2083
Disclosure Date: July 05, 2005 (last updated February 22, 2025)
Format string vulnerability in IMAP4 in IA eMailServer Corporate Edition 5.2.2 build 1051 allows remote attackers to cause a denial of service (application crash) via a LIST command with format string specifiers as the second argument.
0
Attacker Value
Unknown
CVE-2005-1103
Disclosure Date: April 12, 2005 (last updated February 22, 2025)
Sygate Security Agent (SSA) in Sygate Secure Enterprise 3.5 through 4.1 does not prevent the security policy from being updated by unprivileged users, which allows local users to modify the policy by exporting the policy file, changing it, and importing it back into SSA.
0
Attacker Value
Unknown
CVE-2005-0249
Disclosure Date: February 08, 2005 (last updated February 22, 2025)
Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header.
0
Attacker Value
Unknown
CVE-2004-2348
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Sybari AntiGen for Domino 7.0 Build 722 SR2 allows remote attackers to cause a denial of service (hang) via an encrypted ZIP file with the "include full path info" option set, as used by certain variants of the Beagle/Bagle worm.
0