Author: joeyh Date: 2005-12-29 21:14:22 +0000 (Thu, 29 Dec 2005) New Revision: 3180 Modified: data/CVE/list Log: automatic update Modified: data/CVE/list ==================================================================--- data/CVE/list 2005-12-29 20:47:30 UTC (rev 3179) +++ data/CVE/list 2005-12-29 21:14:22 UTC (rev 3180) @@ -1,6 +1,247 @@ +CVE-2006-0053 + RESERVED +CVE-2006-0052 + RESERVED +CVE-2006-0051 + RESERVED +CVE-2006-0050 + RESERVED +CVE-2006-0049 + RESERVED +CVE-2006-0048 + RESERVED +CVE-2006-0047 + RESERVED +CVE-2006-0046 + RESERVED +CVE-2006-0045 + RESERVED +CVE-2006-0044 + RESERVED +CVE-2005-4585 (Unspecified vulnerability in the GTP dissector for Ethereal 0.9.1 to ...) + TODO: check +CVE-2005-4584 (BZFlag server 2.0.4 and earlier allows remote attackers to cause a ...) + TODO: check +CVE-2005-4583 (Unspecified vulnerability in the Management Interface in VMware ESX ...) + TODO: check +CVE-2005-4582 (Electric Sheep 2.6.3 does not require authentication or integrity ...) + TODO: check +CVE-2005-4581 (Buffer overflow in Electric Sheep 2.6.3 client allows local users to ...) + TODO: check +CVE-2005-4580 (Cross-site scripting (XSS) vulnerability in Day Communique 4 allows ...) + TODO: check +CVE-2005-4579 (Multiple HTTP response splitting vulnerabilities in Hitachi Business ...) + TODO: check +CVE-2005-4578 (Multiple SQL injection vulnerabilities in Hitachi Business Logic - ...) + TODO: check +CVE-2005-4577 (Multiple cross-site scripting (XSS) vulnerabilities in Hitachi ...) + TODO: check +CVE-2005-4576 (Multiple cross-site scripting (XSS) vulnerabilities in the ...) + TODO: check +CVE-2005-4575 (PaperThin CommonSpot Content Server 4.5 and earlier allow remote ...) + TODO: check +CVE-2005-4574 (Cross-site scripting (XSS) vulnerability in loader.cfm in PaperThin ...) + TODO: check +CVE-2005-4573 (PHP remote file include vulnerability in plog-admin-functions.php in ...) + TODO: check +CVE-2005-4572 (Multiple SQL injection vulnerabilities in myEZshop Shopping Cart allow ...) + TODO: check +CVE-2005-4571 (Cross-site scripting (XSS) vulnerability in myEZshop Shopping Cart ...) + TODO: check +CVE-2005-4570 (The Internet Key Exchange version 1 (IKEv1) implementations in ...) + TODO: check +CVE-2005-4569 (Stack-based buffer overflow in index.fts in FTGate Technology ...) + TODO: check +CVE-2005-4568 (Multiple format string vulnerabilities in FTGate Technology (formerly ...) + TODO: check +CVE-2005-4567 (Multiple cross-site scripting (XSS) vulnerabilities in FTGate ...) + TODO: check +CVE-2005-4566 (Buffer overflow in the Internet Key Exchange version 1 (IKEv1) ...) + TODO: check +CVE-2005-4565 (Format string vulnerability in the Internet Key Exchange version 1 ...) + TODO: check +CVE-2005-4564 (The Internet Key Exchange version 1 (IKEv1) implementation in ADTRAN ...) + TODO: check +CVE-2005-4563 (SQL injection vulnerability in main.php in Enterprise Heart Enterprise ...) + TODO: check +CVE-2005-4562 + RESERVED +CVE-2005-4561 + RESERVED +CVE-2005-4560 (Microsoft Windows allows remote attackers to execute arbitrary code ...) + TODO: check +CVE-2005-4559 (mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail ...) + TODO: check +CVE-2005-4558 (IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and ...) + TODO: check +CVE-2005-4557 (dir/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail ...) + TODO: check +CVE-2005-4556 (PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as ...) + TODO: check +CVE-2005-4555 (Cross-site scripting (XSS) vulnerability in add.php in DEV web ...) + TODO: check +CVE-2005-4554 (Multiple SQL injection vulnerabilities in DEV web management system ...) + TODO: check +CVE-2005-4553 (Buffer overflow in Golden FTP Server 1.92 allows remote attackers to ...) + TODO: check +CVE-2005-4552 (The (1) slsmgr and (2) slsadmin programs in Sun Solaris PC NetLink 2.0 ...) + TODO: check +CVE-2005-4551 (Cross-site scripting (XSS) vulnerability in sign.php in codegrrl ...) + TODO: check +CVE-2005-4550 (The PORTAL schema in Oracle Application Server (OracleAS) Discussion ...) + TODO: check +CVE-2005-4549 (Cross-site scripting (XSS) vulnerability in Oracle Application Server ...) + TODO: check +CVE-2005-4548 (SQL injection vulnerability in the "user area" in RWS Statistics ...) + TODO: check +CVE-2005-4547 (Cross-site scripting (XSS) vulnerability in home/search.php in eggblog ...) + TODO: check +CVE-2005-4546 (search.php in eggblog 2.0 allows remote attackers to obtain the full ...) + TODO: check +CVE-2005-4545 (Cross-site scripting (XSS) vulnerability in search.asp in NetDirect ...) + TODO: check +CVE-2005-4544 + RESERVED +CVE-2005-4543 + RESERVED +CVE-2005-4542 + RESERVED +CVE-2005-4541 + RESERVED +CVE-2005-4540 + RESERVED +CVE-2005-4539 + RESERVED +CVE-2005-4538 + RESERVED +CVE-2005-4537 + RESERVED +CVE-2005-4536 + RESERVED +CVE-2005-4535 + RESERVED +CVE-2005-4533 (Argument injection vulnerability in scponlyc in scponly 4.1 and ...) + TODO: check +CVE-2005-4532 (scponlyc in scponly 4.1 and earlier, when the operating system ...) + TODO: check +CVE-2005-4531 + REJECTED + TODO: check +CVE-2005-4530 (Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft EPay ...) + TODO: check +CVE-2005-4529 (The Chatspot 2.0.0a7 module for phpBB might allow remote attackers to ...) + TODO: check +CVE-2005-4528 (SQL injection vulnerability in the Chatspot 2.0.0a7 module for phpBB ...) + TODO: check +CVE-2005-4527 (Multiple SQL injection vulnerabilities in Direct News 4.9 allow remote ...) + TODO: check +CVE-2005-4526 (Clearswift MIMEsweeper For Web (a.k.a. WEBsweeper) 4.0 through 5.1 ...) + TODO: check +CVE-2005-4525 (SmcGui.exe in Sygate Protection Agent 5.0 build 6144 allows local ...) + TODO: check +CVE-2005-4524 (Mantis 1.0.0rc3 does not properly handle "Make note private" when a ...) + TODO: check +CVE-2005-4523 (Mantis 1.0.0rc3 and earlier discloses private bugs via public RSS ...) + TODO: check +CVE-2005-4522 (Multiple cross-site scripting (XSS) vulnerabilities in the ...) + TODO: check +CVE-2005-4521 (CRLF injection vulnerability in Mantis 1.0.0rc3 and earlier allows ...) + TODO: check +CVE-2005-4520 (Unspecified "port injection" vulnerabilities in filters in Mantis ...) + TODO: check +CVE-2005-4519 (Multiple SQL injection vulnerabilities in the manage user page ...) + TODO: check +CVE-2005-4518 (Mantis before 0.19.4 allows remote attackers to bypass the file upload ...) + TODO: check +CVE-2005-4517 (SQL injection vulnerability in PHP-Fusion 6.00.200 through 6.00.300 ...) + TODO: check +CVE-2005-4516 (Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion ...) + TODO: check +CVE-2005-4515 (SQL injection vulnerability in WebDB 1.1 and earlier allows remote ...) + TODO: check +CVE-2005-4514 (The encapsulation script mechanism in Webwasher CSM Appliance Suite ...) + TODO: check +CVE-2005-4513 (Cross-site scripting (XSS) vulnerability in WANDSOFT e-SEARCH allows ...) + TODO: check +CVE-2005-4512 (Cross-site scripting (XSS) vulnerability in WAXTRAPP 3.0.1 and earlier ...) + TODO: check +CVE-2005-4511 (Format string vulnerability in TN3270 Resource Gateway 1.1.0 allows ...) + TODO: check +CVE-2005-4510 (Directory traversal vulnerability in server.np in NetPublish Server 7 ...) + TODO: check +CVE-2005-4509 (SQL injection vulnerability in index.asp in pTools allows remote ...) + TODO: check +CVE-2005-4508 (Nexus Concepts Dev Hound 2.24 and earlier allows remote attackers to ...) + TODO: check +CVE-2005-4507 (Multiple cross-site scripting (XSS) vulnerabilities in Nexus Concepts ...) + TODO: check +CVE-2005-4506 (Nexus Concepts Dev Hound 2.24 and earlier stores username and password ...) + TODO: check +CVE-2005-4505 (Unquoted Windows search path vulnerability in McAfee VirusScan ...) + TODO: check +CVE-2005-4504 (The khtml::RenderTableSection::ensureRows function in KHTMLParser in ...) + TODO: check +CVE-2005-4503 (httprint v202, and possibly other versions before v301, allows remote ...) + TODO: check +CVE-2005-4502 (Cross-site scripting (XSS) vulnerability in httprint v202, and ...) + TODO: check +CVE-2005-4501 (MediaWiki before 1.5.4 uses a hard-coded "internal placeholder ...) + TODO: check +CVE-2005-4500 (SQL injection vulnerability in MusicBox 2.3 allows remote attackers to ...) + TODO: check +CVE-2005-4499 (The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 ...) + TODO: check +CVE-2005-4498 (Cross-site scripting (XSS) vulnerability in Text-e 1.6.4 and earlier ...) + TODO: check +CVE-2005-4497 (Cross-site scripting (XSS) vulnerability in Tangora Portal CMS 4.0 and ...) + TODO: check +CVE-2005-4496 (Cross-site scripting (XSS) vulnerability in search in SyntaxCMS 1.2.1 ...) + TODO: check +CVE-2005-4495 (SQL injection vulnerability in index.cfm in SpireMedia mx7 allows ...) + TODO: check +CVE-2005-4494 (Cross-site scripting (XSS) vulnerability in SPIP 1.8.2 and earlier ...) + TODO: check +CVE-2005-4493 (Cross-site scripting (XSS) vulnerability in SpearTek 6.0 and earlier ...) + TODO: check +CVE-2005-4492 (Cross-site scripting (XSS) vulnerability in Starphire SiteSage 5.0.18 ...) + TODO: check +CVE-2005-4491 (Multiple cross-site scripting (XSS) vulnerabilities in Sitekit CMS 6.6 ...) + TODO: check +CVE-2005-4490 (Multiple cross-site scripting (XSS) vulnerabilities in SCOOP! 2.3 and ...) + TODO: check +CVE-2005-4489 (Cross-site scripting (XSS) vulnerability in Scoop 1.1 RC1 and earlier ...) + TODO: check +CVE-2005-4488 (Multiple cross-site scripting (XSS) vulnerabilities in index.tpl in ...) + TODO: check +CVE-2005-4487 (Cross-site scripting (XSS) vulnerability in RAMSite R|1 CMS 1.0 and ...) + TODO: check +CVE-2005-4486 (SQL injection vulnerability in Quantum Art QP7.Enterprise (formerly ...) + TODO: check +CVE-2005-4485 (Multiple cross-site scripting (XSS) vulnerabilities in ProjectApp 3.3 ...) + TODO: check +CVE-2005-4484 (Multiple cross-site scripting (XSS) vulnerabilities in IntranetApp 3.3 ...) + TODO: check +CVE-2005-4483 (Cross-site scripting (XSS) vulnerability in login.asp in SiteEnable ...) + TODO: check +CVE-2005-4482 (Cross-site scripting (XSS) vulnerability in login.asp in PortalApp 3.3 ...) + TODO: check +CVE-2005-4481 (Cross-site scripting (XSS) vulnerability in Polopoly 9 and earlier ...) + TODO: check +CVE-2005-4480 (Cross-site scripting (XSS) vulnerability in Plexcor CMS 4.0 and ...) + TODO: check +CVE-2005-4479 (SQL injection vulnerability in article.php in phpSlash 0.8.1 and ...) + TODO: check +CVE-2005-4478 (Multiple SQL injection vulnerabilities in Papoo 2.1.2 and earlier ...) + TODO: check +CVE-2005-4477 (Cross-site scripting (XSS) vulnerability in papaya CMS 4.0.4 and ...) + TODO: check +CVE-2005-4476 (Cross-site scripting (XSS) vulnerability in store/search/results.html ...) + TODO: check +CVE-2005-4475 (Cross-site scripting (XSS) vulnerability in OpenCms 6.0.3 and earlier ...) + TODO: check CVE-2005-XXXX [privilege escalation in scponly] - scponly <unfixed> (bug #344418) -CVE-2005-4534 [Insecure tempfile in Bugzilla''s syncshadowdb] +CVE-2005-4534 (The shadow database feature (syncshadowdb) in Bugzilla 2.16.7 through ...) - bugzilla 2.18 (bug #329387; low) NOTE: The vulnerable script has been removed in the 2.18 upstream release [woody] - bugzilla <unfixed> @@ -59,7 +300,7 @@ NOT-FOR-US: Beehive Forum CVE-2005-4460 (Cross-site scripting (XSS) vulnerability in Beehive Forum 0.6.2 and ...) NOT-FOR-US: Beehive Forum -CVE-2005-4459 (Heap-based buffer overflow in vmnat.exe and vmnet-natd in VMWare ...) +CVE-2005-4459 (Heap-based buffer overflow in the NAT networking components vmnat.exe ...) NOT-FOR-US: VMWare CVE-2005-4458 (Group.pm in Metadot Portal Server 6.4.4 and earlier does not properly ...) NOT-FOR-US: Metadot Portal Server @@ -88,9 +329,9 @@ NOT-FOR-US: phpCOIN CVE-2005-4446 (Cross-site scripting (XSS) vulnerability in index.asp in ASPBite 8.x ...) NOT-FOR-US: ASPBite -CVE-2005-4445 (Off-by-one error in Pegasus Mail 4.21a through 4.21c and 4.30PB1 allow ...) +CVE-2005-4445 (Off-by-one error in Pegasus Mail 4.21a through 4.21c and 4.30PB1 allows ...) NOT-FOR-US: Pegasus Mail -CVE-2005-4444 (Stack-based buffer overflow in Pegasus Mail 4.21a through 4.21c and ...) +CVE-2005-4444 (Stack-based buffer overflow in the trace message functionality in ...) NOT-FOR-US: Pegasus Mail CVE-2005-4443 (Untrusted search path vulnerability in Gauche before 0.8.6-r1 on ...) - gauche <not-affected> (Gentoo-specific packaging flaw) @@ -2037,14 +2278,13 @@ NOT-FOR-US: Mac OS X CVE-2005-3664 (Heap-based buffer overflow in Kaspersky Anti-Virus Engine, as used in ...) NOT-FOR-US: Kaspersky AV -CVE-2005-3663 (Untrusted Windows search path vulnerability in Kaspersky Anti-Virus ...) +CVE-2005-3663 (Unquoted Windows search path vulnerability in Kaspersky Anti-Virus 5.0 ...) NOT-FOR-US: Kaspersky AV CVE-2005-3662 (Off-by-one buffer overflow in pnmtopng before 2.39, when using the ...) - netpbm-free <unfixed> (medium) CVE-2005-3661 (Dell TrueMobile 2300 Wireless Broadband Router running firmware ...) NOT-FOR-US: Dell hardware issue -CVE-2005-3660 [Linux Kernel Socket Buffer Memory Exhaustion DoS Vulnerability] - RESERVED +CVE-2005-3660 (Linux kernel 2.4 and 2.6 allows attackers to cause a denial of service ...) - linux-2.6 <unfixed> - kernel-source-2.4.27 <unfixed> CVE-2005-3659 @@ -2290,20 +2530,16 @@ RESERVED CVE-2005-3538 RESERVED -CVE-2005-3537 [In phpBB2 before 2.0.18, remote can read and edit private messages of other users] - RESERVED +CVE-2005-3537 (A "missing request validation" error in phpBB 2 before 2.0.18 allows ...) {DSA-925-1} - phpbb2 2.0.18-1 (bug #336582; medium) -CVE-2005-3536 [SQL injection in phpBB2 before 2.0.18, via $topic_type in posting.php] - RESERVED +CVE-2005-3536 (SQL injection vulnerability in phpBB 2 before 2.0.18 allows remote ...) {DSA-925-1} - phpbb2 2.0.18-1 (bug #336582; medium) -CVE-2005-3535 [buffer overflow in ketm, leading to group games privileges] - RESERVED +CVE-2005-3535 (Buffer overflow in KETM 0.0.6 allows local users to execute arbitrary ...) {DSA-926-1} - ketm 0.0.6-17sarge1 (low) -CVE-2005-3534 [buffer overflow in the NBD server] - RESERVED +CVE-2005-3534 (Buffer overflow in the Network Block Device (nbd) server 2.7.5 and ...) {DSA-924-1} - nbd 1:2.8.3-1 CVE-2005-3533 (Buffer overflow in OSH before 1.7-15 allows local users to execute ...) @@ -3038,14 +3274,12 @@ CVE-2005-3346 (Buffer overflow in the environment variable substitution code in ...) {DSA-918-1} - osh 1.7-15 (bug #338312; medium) -CVE-2005-3345 [privilege escalation in rssh] - RESERVED +CVE-2005-3345 (rssh 2.0.0 through 2.2.3 allows local users to bypass access ...) - rssh 2.3.0-1 (bug #344395; bug #344424) CVE-2005-3344 (The default installation of Horde 3.0.4 contains an administrative ...) {DSA-884-1} - horde3 3.0.5-2 (bug #332290; bug #332289; medium) -CVE-2005-3343 [Insecure temp files in tkdiff] - RESERVED +CVE-2005-3343 (tkdiff before 4.1.1 allows local users to overwrite arbitrary files ...) {DSA-927-1} - tkdiff 1:4.0.2-2 (low) CVE-2005-3342 @@ -3063,8 +3297,7 @@ - mozilla-firefox <unfixed> (bug #336171; low) - firefox 1.4.99+1.5rc3.dfsg-2 (bug #336171; low) NOTE: Only a DoS attack, see http://bugzilla.mozilla.org/show_bug.cgi?id=303433 -CVE-2005-3341 [Insecure temp files in dhis-tools-dns] - RESERVED +CVE-2005-3341 (DHIS tools DNS package (dhis-tools-dns) before 5.0 allows local users ...) {DSA-928-1} - dhis-tools-dns 5.0-5 CVE-2005-XXXX [xdm: full-force SAINT attack crashes xdm] @@ -3147,7 +3380,7 @@ NOT-FOR-US: Microsoft CVE-2005-3311 (BMC Software Control-M 6.1.03 for Solaris, and possibly other ...) NOT-FOR-US: BMC Software Control-M -CVE-2005-3310 (Multiple interpretation error in phpBB 2.0.17, with remote avatars and ...) +CVE-2005-3310 (Interpretation conflict in phpBB 2.0.17, with remote avatars and ...) {DSA-925-1} - phpbb2 2.0.18-1 (bug #335662; low) CVE-2005-3309 (Multiple SQL injection vulnerabilities in Zomplog 3.4 allow remote ...) @@ -4291,17 +4524,17 @@ REJECTED CVE-2005-2941 RESERVED -CVE-2005-2940 (Untrusted Windows search path vulnerability in Microsoft Antispyware ...) +CVE-2005-2940 (Unquoted Windows search path vulnerability in Microsoft Antispyware ...) NOT-FOR-US: Microsoft Antispyware -CVE-2005-2939 (Untrusted Windows search path vulnerability in VMWare Workstation ...) +CVE-2005-2939 (Unquoted Windows search path vulnerability in VMWare Workstation 5.0.0 ...) NOT-FOR-US: VMWare -CVE-2005-2938 (Untrusted Windows search path vulnerability in iTunesHelper.exe in ...) +CVE-2005-2938 (Unquoted Windows search path vulnerability in iTunesHelper.exe in ...) NOT-FOR-US: iTunes CVE-2005-2937 REJECTED -CVE-2005-2936 (Untrusted Windows search path vulnerability in RealNetworks RealPlayer ...) +CVE-2005-2936 (Unquoted Windows search path vulnerability in RealNetworks RealPlayer ...) NOT-FOR-US: Real Player -CVE-2005-2935 (AntiSpywareMain.exe in Microsoft AntiSpyware does not quote the C ...) +CVE-2005-2935 (Unquoted Windows search path vulnerability in Microsoft AntiSpyware ...) NOT-FOR-US: Microsoft AntiSpyware CVE-2005-2934 RESERVED @@ -7527,7 +7760,7 @@ {DSA-805-1 DSA-803-1} - apache 1.3.33-8 (bug #322607; medium) - apache2 2.0.54-5 (bug #316173; medium) -CVE-2005-2087 (Internet Explorer 6.0.2900.2180 on Windows XP allows remote attackers ...) +CVE-2005-2087 (Internet Explorer 5.01 SP4 up to 6 on various Windows operating ...) NOT-FOR-US: Microsoft CVE-2005-2086 (PHP remote file inclusion vulnerability in viewtopic.php in phpBB ...) - phpbb2 <not-affected> (phpbb versions in Debian not affected) @@ -10993,7 +11226,7 @@ NOT-FOR-US: ACS Blog CVE-2005-1287 (Multiple SQL injection vulnerabilities in BK Forum 4.0 allow remote ...) NOT-FOR-US: BK Forum -CVE-2005-1286 (BitDefender 8 allows local users to prevent BitDefender from starting ...) +CVE-2005-1286 (Unquoted Windows search path vulnerability in BitDefender 8 allows ...) NOT-FOR-US: Bitdefender CVE-2005-1285 (Cross-site scripting (XSS) vulnerability in thread.php in WoltLab ...) NOT-FOR-US: Woltlab Burning Board @@ -11361,7 +11594,7 @@ NOT-FOR-US: WinHex CVE-2005-1186 (Musicmatch Jukebox 10.00.2047 and earlier adds the musicmatch.com ...) NOT-FOR-US: Musicmatch -CVE-2005-1185 (MMFWLaunch.exe in Musicmatch Jukebox 10.00.2047 and earlier does not ...) +CVE-2005-1185 (Unquoted Windows search path vulnerability in Musicmatch Jukebox ...) NOT-FOR-US: Musicmatch CVE-2005-1184 (The TCP/IP stack in multiple operating systems allows remote attackers ...) NOT-FOR-US: Apparently bogus report. at least on Linux it couldn''t be reproduced