CVE-2005-1530
Sophos Anti-Virus 5.0.1, with "Scan inside archive files" enabled, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a Bzip2 archive with a large ‘Extra field length’ value....
Sophos Anti-Virus 5.0.1, with "Scan inside archive files" enabled, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a Bzip2 archive with a large ‘Extra field length’ value....
phpMyFAQ 1.4.0 allows remote attackers to access the Image Manager to upload or delete images without authorization via a direct request. Date published : 2005-07-17 http://www.securityfocus.com/bid/10813 http://www.phpmyfaq.de/advisory_2004-07-27.php
Directory traversal vulnerability in phpMyFAQ 1.4.0 alpha allows remote attackers to read arbitrary files, and possibly execute local PHP files, via .. sequences in the lang (language) variable. Date published : 2005-07-17 http://www.securityfocus.com/bid/10377 http://www.securityfocus.com/archive/1/363636
Directory traversal vulnerability in phpMyFAQ 1.3.12 allows remote attackers to read arbitrary files, and possibly execute local PHP files, via the action variable, which is used as part of a template filename. Date published...
SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration interface via a direct request to admin.cgi with a modified utoken parameter. Date published :...
Directory traversal vulnerability in user.cgi in SurgeLDAP 1.0g and earlier allows remote attackers to read arbitrary files via a .. in the page parameter of the show command. Date published : 2005-07-17 http://www.securityfocus.com/bid/10103 http://members.lycos.co.uk/r34ct/main/SurgeLDAP%201.0g.txt
The firewall in Astaro Security Linux before 4.024 sends responses to SYN-FIN packets, which makes it easier for remote attackers to obtain information about the system and construct specialized attacks. Date published : 2005-07-17...
The PPTP server in Astaro Security Linux before 4.024 provides information about its version, which makes it easier for remote attackers to construct specialized attacks. Date published : 2005-07-17 http://www.astaro.org/showflat.php?Cat=&Number=51459&page=0&view=collapsed&sb=5&o=&fpart=1#51459 http://www.osvdb.org/11406
Unknown vulnerability in the "access code" in RemoteEditor before 0.1.6 has unknown impact and attack vectors, possibly involving a bypass of IP address restrictions. Date published : 2005-07-17 http://sourceforge.net/project/shownotes.php?group_id=98629&release_id=279743 http://www.osvdb.org/11445
Unknown vulnerability in the "access code" in SecureEditor before 0.1.2 has unknown impact and attack vectors, possibly involving a bypass of IP address restrictions. Date published : 2005-07-17 http://sourceforge.net/project/shownotes.php?group_id=98629&release_id=279733 http://www.osvdb.org/11445
Unknown vulnerability in RemoteEditor before 0.1.1 has unknown impact and attack vectors, related to "oversize submissions." Date published : 2005-07-17 http://sourceforge.net/project/shownotes.php?group_id=98629&release_id=279743 http://www.osvdb.org/11444
Unknown vulnerability in the "admin of paypal email addresses" in AudienceConnect before 1.0.beta.21 has unknown impact and attack vectors. Date published : 2005-07-17 http://sourceforge.net/project/shownotes.php?group_id=98629&release_id=279700 http://www.osvdb.org/11443
Cross-site scripting (XSS) vulnerability in Goollery before 0.04b allows remote attackers to inject arbitrary HTML or web script via the conversation_id parameter to viewpic.php. Date published : 2005-07-17 http://www.osvdb.org/ref/11/11624-goollery-viewpic.txt http://www.osvdb.org/11624
Cross-site scripting (XSS) vulnerability in Goollery 0.03 allows remote attackers to inject arbitrary HTML or web script via the (1) page parameter to viewalbum.php or (2) btopage parameter to viewpic.php. Date published : 2005-07-17...