Monthly Archive: April 2005

CVE-2005-1097

Rebrand P2P Share Spy 2.2 stores the user password in plaintext in the txtPassword value in the registry, which allows local users to gain privileges. Date published : 2005-04-13 http://securitytracker.com/id?1013673

CVE-2005-1091

Maxthon 1.2.0 and 1.2.1 allows remote attackers to bypass the security ID and use restricted plugin API functions via script that includes the max.src file into the source page. Date published : 2005-04-13 http://www.securityfocus.com/bid/13073...

CVE-2005-1087

CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide entries in the logfile, and possibly read files using an injected type command, via CRLF...

CVE-2005-0610

Multiple symlink vulnerabilities in portupgrade before 20041226_2 in FreeBSD allow local users to (1) overwrite arbitrary files and possibly replace packages to execute arbitrary code via pkg_fetch, (2) overwrite arbitrary files via temporary files...

CVE-2005-0562

GIF file validation error in MSN Messenger 6.2 allows remote attackers in a user’s contact list to execute arbitrary code via a GIF image with an improper height and width. Date published : 2005-04-13...