Advisories
GoogleActive exploitation (sightings)CRITICAL2005-11-22
The Saxon XSLT parser in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to obtain sensitive information and execute arbitrary code via dangerous Java class methods in select attribute of xsl:value-of tags in...
CVEs:CVE-2005-3757
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mini_search_appliance |
affected |
google |
— |
— |
| search_appliance |
affected |
google |
— |
— |
GooglePoC exploitCRITICAL2005-11-22
Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to inject arbitrary Javascript, and possibly other web script or HTML, via a proxystylesheet variable that contains ...
CVEs:CVE-2005-3758
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mini_search_appliance |
affected |
google |
— |
— |
| search_appliance |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2005-11-22
Directory traversal vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to determine the existence of arbitrary files via a relative path from a style sheet directory, then comparing the resultin...
CVEs:CVE-2005-3755
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mini_search_appliance |
affected |
google |
— |
— |
| search_appliance |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2005-11-29
Cross-site scripting (XSS) vulnerability in index.php in Google API Search 1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via hex-encoded values in the REQ parameter.
CVEs:CVE-2005-3869
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| api_search |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2005-11-22
Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to inject arbitrary Javascript, and possibly other web script or HTML, via the proxystylesheet variable, which will ...
CVEs:CVE-2005-3754
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mini_search_appliance |
affected |
google |
— |
— |
| search_appliance |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2005-11-22
Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to port scan arbitrary hosts via URLs with modified targets and ports, then comparing the resulting error messages to determine open and closed ports.
CVEs:CVE-2005-3756
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mini_search_appliance |
affected |
google |
— |
— |
| search_appliance |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2005-11-18
Google Talk before 1.0.0.76, with email notification enabled, allows remote attackers to cause a denial of service (connection reset) via email with a blank sender.
CVEs:CVE-2005-3678
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| talk |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2005-11-29
The automatic update feature in Google Talk allows remote attackers to cause a denial of service (CPU and memory consumption) by poisoning a target's DNS cache and causing a large update file to be sent, which consumes large amounts of CPU and memory d...
CVEs:CVE-2005-3899
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| talk |
affected |
google |
— |
— |