CVE-2005-2022
published 2005-06-17CVE-2005-2022: Unknown vulnerability in Webmail in iPlanet Messaging Server 5.2 Patch 1 and Sun ONE Messaging Server 6.2 allows remote attackers to execute arbitrary…
PriorityP415medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
0.94%
56.7th percentile
Unknown vulnerability in Webmail in iPlanet Messaging Server 5.2 Patch 1 and Sun ONE Messaging Server 6.2 allows remote attackers to execute arbitrary Javascript, possibly due to a cross-site scripting (XSS) vulnerability.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | sylabs_sif_v2 | >= 0 < 2.8.1 | 2.8.1 |
| sun | iplanet_messaging_server | — | — |
| sun | one_messaging_server | — | — |
| sun | one_messaging_server | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
ghsa5.0MEDIUM
cisa9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
SIF's Digital Signature Hash Algorithms Not Validated
ghsa·2022-10-06·CVSS 5.0
CVE-2022-39237 [MEDIUM] CWE-327 SIF's Digital Signature Hash Algorithms Not Validated
SIF's Digital Signature Hash Algorithms Not Validated
### Impact
The `github.com/sylabs/sif/v2/pkg/integrity` package does not verify that the hash algorithm(s) used are cryptographically secure when verifying digital signatures.
### Patches
A patch is available in version >= v2.8.1 of the module. Users are encouraged to upgrade.
The patch is commit https://github.com/sylabs/sif/commit/07fb86029a12e3210f6131e065570124605daeaa
### Workarounds
Users may independently validate that the hash algorithm(s) used for metadata digest(s) and signature hash are cryptographically secure.
### References
* [CVE-2004-2761](https://nvd.nist.gov/vuln/detail/cve-2004-2761)
* [CVE-2005-4900](https://nvd.nist.gov/vuln/detail/cve-2005-4900)
### For more information
If you have any questions or comme
GHSA
GHSA-c86q-px74-v8w3: Unknown vulnerability in Webmail in iPlanet Messaging Server 5
ghsa_unreviewed·2022-05-01
CVE-2005-2022 [MEDIUM] CWE-79 GHSA-c86q-px74-v8w3: Unknown vulnerability in Webmail in iPlanet Messaging Server 5
Unknown vulnerability in Webmail in iPlanet Messaging Server 5.2 Patch 1 and Sun ONE Messaging Server 6.2 allows remote attackers to execute arbitrary Javascript, possibly due to a cross-site scripting (XSS) vulnerability.
GHSA
GHSA-xf68-pxg8-qfjf: Webmail in Sun ONE Messaging Server 6
ghsa_unreviewed·2022-04-29·CVSS 4.3
CVE-2004-2766 [MEDIUM] CWE-200 GHSA-xf68-pxg8-qfjf: Webmail in Sun ONE Messaging Server 6
Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02 allows remote attackers to obtain unspecified "access" to e-mail via a crafted e-mail message, related to a "session hijacking" issue, a different vulnerability than CVE-2005-2022 and CVE-2006-5486.
GHSA
GHSA-547m-mqmc-2jqg: Cross-site scripting (XSS) vulnerability in Webmail in Sun ONE Messaging Server 6
ghsa_unreviewed·2022-04-29·CVSS 4.3
CVE-2004-2765 [MEDIUM] CWE-79 GHSA-547m-mqmc-2jqg: Cross-site scripting (XSS) vulnerability in Webmail in Sun ONE Messaging Server 6
Cross-site scripting (XSS) vulnerability in Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, a different vulnerability than CVE-2005-2022 and CVE-2006-5486.
CISA
Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability
cisa·2022-03-28·CVSS 7.8
CVE-2011-2005 [HIGH] CWE-264 Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability
Vulnerability: Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability
Affected: Microsoft Ancillary Function Driver (afd.sys)
afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2011-2005
Remediation Due Date: 2022-04-18
CISA
HP OpenView Network Node Manager Remote Code Execution Vulnerability
cisa·2022-03-25·CVSS 9.8
CVE-2005-2773 [CRITICAL] HP OpenView Network Node Manager Remote Code Execution Vulnerability
Vulnerability: HP OpenView Network Node Manager Remote Code Execution Vulnerability
Affected: Hewlett Packard (HP) OpenView Network Node Manager
HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2005-2773
Remediation Due Date: 2022-04-15
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2005-06-17
Published