Skip to main content

CWE archive

CWE-264 CVEs

Programmatic archive

5,486 CVEs tagged with CWE-264526 Critical, 1,825 High, 2,660 Medium, 475 Low, 0 Unrated.

CVE-2005-4854

Published Dec 31, 2005

eZ publish 3.5 through 3.7 before 20050830 does not use a folder's read permissions to restrict notifications, which allows remote authenticated users to obtain sensitive informat…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4855

Published Dec 31, 2005

Unrestricted file upload vulnerability in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050922 does not restrict Image datatype uploads to i…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-4871

Published Dec 31, 2005

Certain XML functions in IBM DB2 8.1 run with the privileges of DB2 instead of the logged-in user, which allows remote attackers to create or overwrite files via (1) XMLFileFromVa…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4217

Published Dec 14, 2005

Perl in Apple Mac OS X Server 10.3.9 does not properly drop privileges when using the "$<" variable to set uid, which allows attackers to gain privileges.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4089

Published Dec 8, 2005

Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4069

Published Dec 8, 2005

SunnComm MediaMax DRM 5.0.21.0, as used by Sony BMG, assigns insecure Everyone/Full Control permissions to the "SunnComm Shared" directory, which allows local users to gain privil…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2929

Published Nov 18, 2005

Lynx 2.8.5, and other versions before 2.8.6dev.15, allows remote attackers to execute arbitrary commands via (1) lynxcgi:, (2) lynxexec, and (3) lynxprog links, which are not prop…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2938

Published Nov 18, 2005

Unquoted Windows search path vulnerability in iTunesHelper.exe in iTunes 4.7.1.30 and iTunes 5 for Windows might allow local users to gain privileges via a malicious C:\program.ex…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-3567

Published Nov 16, 2005

slapd daemon in IBM Tivoli Directory Server (ITDS) 5.2.0 and 6.0.0 binds using SASL EXTERNAL, which allows attackers to bypass authentication and modify and delete directory data…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2959

Published Oct 25, 2005

Incomplete blacklist vulnerability in sudo 1.6.8 and earlier allows local users to gain privileges via the (1) SHELLOPTS and (2) PS4 environment variables before executing a bash…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3273

Published Oct 21, 2005

The rose_rt_ioctl function in rose_route.c for Radionet Open Source Environment (ROSE) in Linux 2.6 kernels before 2.6.12, and 2.4 before 2.4.29, does not properly verify the ndig…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3257

Published Oct 18, 2005

The VT implementation (vt_ioctl.c) in Linux kernel 2.6.12, and possibly other versions including 2.6.14.4, allows local users to use the KDSKBSENT ioctl on terminals of other user…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3179

Published Oct 12, 2005

drm.c in Linux kernel 2.6.10 to 2.6.13 creates a debug file in sysfs with world-readable and world-writable permissions, which allows local users to enable DRM debugging and obtai…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0139

Published Sep 21, 2005

Unknown vulnerability in rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not sufficiently restrict access rights for read-mostly exports, which allows attackers to conduct…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2819

Published Sep 7, 2005

DownFile 1.3 allows remote attackers to gain administrator privileges via a direct request to (1) update.php, (2) del.php, and (3) add_form.php.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2555

Published Aug 16, 2005

Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct unauthorized activities via…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2071

Published Jun 29, 2005

traceroute in Sun Solaris 10 on x86 systems allows local users to execute arbitrary code with PRIV_NET_RAWACCESS privileges via (1) a large number of -g arguments or (2) a malform…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2072

Published Jun 29, 2005

The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setuid or setgid programs, which allows local users to gain privileges by (1) modify…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1532

Published May 12, 2005

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1425

Published May 3, 2005

Uapplication Uguestbook 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct req…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 5,376-5,400 of 5,486 CVEsPage 216 of 220