CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2005-4653

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in ss.php in AL-Caricatier 2.5 and earlier allows remote attackers to bypass login authentication by requesting view_caricatier.php, and then requesting any file in the admin directory with a cookie_username=admin argument.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4661

    Last Modified: 16 Apr 2026

    The notifyendsubs cron job in Campsite before 2.3.3 sends an e-mail message containing a certain unencrypted MySQL password, which allows remote attackers to sniff the password.

    Published: 31 Dec 2005
    4.6
    Medium

    CVE-2005-4668

    Last Modified: 16 Apr 2026

    The embedded HSQLDB in ParosProxy before 3.2.7, when running with JDK 1.4.2 before 1.4.2_08, allows local users to execute arbitrary comands via crafted SQL commands that interact with HSQLDB through JDBC, a similar vulnerability to CVE-2003-0845.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4677

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in additional_images.php (aka the Additional Images module) before 1.14 in osCommerce allows remote attackers to execute arbitrary SQL commands via the products_id parameter to product_info.php.

    Published: 31 Dec 2005
    6.4
    Medium

    CVE-2005-4699

    Last Modified: 16 Apr 2026

    Argument injection vulnerability in TellMe 1.2 and earlier allows remote attackers to modify command line arguments for the Whois program and obtain sensitive information via "--" style options in the q_Host parameter.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4700

    Last Modified: 16 Apr 2026

    TellMe 1.2 and earlier, when the Server (o_Server) and HEAD (o_Head) options are enabled, allows remote attackers to obtain sensitive information via an invalid q_Host parameter, which reveals the full pathname of the application in an fsockopen error message.

    Published: 31 Dec 2005
    4.6
    Medium

    CVE-2005-4710

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in multiple Autodesk and AutoCAD products and product families from 2006 and earlier allows remote attackers to "gain inappropriate access to another local user's computer," aka ID DL5549329.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4741

    Last Modified: 16 Apr 2026

    NetBSD 1.6, NetBSD 2.0 through 2.1, and NetBSD-current before 20051031 allows local users to gain privileges by attaching a debugger to a setuid/setgid (P_SUGID) process that performs an exec without a reset of real credentials.

    Published: 31 Dec 2005
    4.9
    Medium

    CVE-2005-4742

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Echelog 0.6.2 allows attackers to "exploit function stacks on some architectures," with unknown impact and attack vectors.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4750

    Last Modified: 16 Apr 2026

    BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP5 and earlier, and 6.1 SP7 and earlier allow remote attackers to cause a denial of service (server thread hang) via unknown attack vectors.

    Published: 31 Dec 2005
    4
    Medium

    CVE-2005-4758

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the Administration server in BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier allows remote authenticated Admin users to read arbitrary files via unknown attack vectors related to an "internal servlet" accessed through HTTP.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4737

    Last Modified: 16 Apr 2026

    IBM DB2 Universal Database (UDB) 820 before ESE AIX 5765F4100 allows remote authenticated users to cause a denial of service (CPU consumption) by "abnormally" terminating a connection, which prevents db2agents from being properly cleared.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4775

    Last Modified: 16 Apr 2026

    Michael Scholz and Sebastian Stein Contineo 2.0, when the admin account lacks an e-mail address attribute, displays the password hash in a warning upon page reload, which might allow remote attackers to view the hash.

    Published: 31 Dec 2005
    3.6
    Low

    CVE-2005-4779

    Last Modified: 16 Apr 2026

    verifiedexecioctl in verified_exec.c in NetBSD 2.0.2 calls NDINIT with UIO_USERSPACE rather than UID_SYSSPACE, which removes the functionality of the verified exec kernel subsystem and might allow local users to execute Trojan horse programs.

    Published: 31 Dec 2005
    2.1
    Low

    CVE-2005-4783

    Last Modified: 16 Apr 2026

    kernfs_xread in kernfs_vnops.c in NetBSD before 20050831 does not check for a negative offset when reading the message buffer, which allows local users to read arbitrary kernel memory.

    Published: 31 Dec 2005
    4.3
    Medium

    CVE-2005-4785

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in QuickBlogger 1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) author ("your name") and (2) "comment" section.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4793

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in the web utility function in Hitachi Cm2/Network Node Manager and JP1/Cm2/Network Node Manager before 20050930 allow attackers to execute arbitrary commands, disable services, and "exploit vulnerabilities."

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4810

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 7.0 Beta3 and earlier allows remote attackers to cause a denial of service (crash) via a "text/html" HTML Content-type header sent in response to an XMLHttpRequest (AJAX).

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4813

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Report Application Server (Crystalras.exe) before 11.0.0.1370, as used in Business Objects Crystal Reports XI, Crystal Reports Server XI, and BusinessObjects Enterprise XI, allows remote attackers to cause a denial of service (application hang) via certain network traffic, possibly involving multiple simultaneous TCP connections.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4815

    Last Modified: 16 Apr 2026

    SAP 6.4 before 6.40 patch 4, 6.2 before 6.20 patch 1364, 4.6 before 4.6D patch 1767, 45 before 45B patch 913, 40 before 40B patch 1008, and 31 before 31I patch 735 do not properly restrict process execution by lnaxdm/sapsys, which allows remote attackers to execute arbitrary code via a certain UDP packet that ends with the name of a local executable file, aka the "FX SAP R/3 gwrd vuln."

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4816

    Last Modified: 16 Apr 2026

    Buffer overflow in mod_radius in ProFTPD before 1.3.0rc2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4818

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Copernicus Europa allow remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4834

    Last Modified: 16 Apr 2026

    IBM WebSphere Application Server (WAS) 5.0.2.5 through 5.1.1.3 allows remote attackers to obtain JSP source code and other sensitive information, related to incorrect request processing by the web container.

    Published: 31 Dec 2005
    7.1
    High

    CVE-2005-4842

    Last Modified: 16 Apr 2026

    The System Monitor Source Properties control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.

    Published: 31 Dec 2005
    6.8
    Medium

    CVE-2005-4866

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in JDBC Applet Server in IBM DB2 8.1 allows remote attackers to execute arbitrary by connecting and sending a long username, then disconnecting gracefully and reconnecting and sending a short username and an unexpected db2java.zip version, which causes a null terminator to be removed and leads to the overflow.

    Published: 31 Dec 2005
    4.3
    Medium

    CVE-2005-4874

    Last Modified: 16 Apr 2026

    The XMLHttpRequest object in Mozilla 1.7.8 supports the HTTP TRACE method, which allows remote attackers to obtain (1) proxy authentication passwords via a request with a "Max-Forwards: 0" header or (2) arbitrary local passwords on the web server that hosts this object.

    Published: 31 Dec 2005
    5.1
    Medium

    CVE-2005-4648

    Last Modified: 16 Apr 2026

    Buffer overflow in Illustrate dBpowerAMP Music Converter 11.5 and earlier, possibly including (1) MusicConverter.exe, (2) playlist.exe, and (3) amp.exe, allows user-assisted attackers to cause a denial of service or execute arbitrary code via a .m3u playlist with a long entry, possibly involving large field names, as demonstrated by SecuBox.Labs.m3u. NOTE: this issue might be the same as the .m3u vulnerability in CVE-2004-1569, but if so, then CD:SF-LOC suggests creating a different identifier since the .m3u issue would affect different versions than the .pls issue.

    Published: 31 Dec 2005
    6.4
    Medium

    CVE-2005-4654

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Oracle for OpenView (OfO) 8.1.7, 9.1.01, and 9.2, and OfO for Linux, allow remote attackers to have an unknown impact via unknown attack vectors. NOTE: because of the lack of details in the vendor advisory, it is unclear which set of existing CVEs this advisory might refer to.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4669

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in RT Internet Solutions (RTIS) WebAdmin allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.

    Published: 31 Dec 2005
    6.4
    Medium

    CVE-2005-4684

    Last Modified: 16 Apr 2026

    Konqueror can associate a cookie with multiple domains when the DNS resolver has a non-root domain in its search list, which allows remote attackers to trick a user into accepting a cookie for a hostname formed via search-list expansion of the hostname entered by the user, or steal a cookie for an expanded hostname, as demonstrated by an attacker who operates an ap1.com Internet web site to steal cookies associated with an ap1.com.example.com intranet web site.

    Published: 31 Dec 2005
    6.4
    Medium

    CVE-2005-4685

    Last Modified: 16 Apr 2026

    Firefox and Mozilla can associate a cookie with multiple domains when the DNS resolver has a non-root domain in its search list, which allows remote attackers to trick a user into accepting a cookie for a hostname formed via search-list expansion of the hostname entered by the user, or steal a cookie for an expanded hostname, as demonstrated by an attacker who operates an ap1.com Internet web site to steal cookies associated with an ap1.com.example.com intranet web site.

    Published: 31 Dec 2005
    7.2
    High

    CVE-2005-4708

    Last Modified: 16 Apr 2026

    Adobe Macromedia MX 2004 products, Captivate, Contribute 2, Contribute 3, and eLicensing client install the Macromedia Licensing Service with the Users group permitted to configure the service, including the path to executable, which allows local users to execute arbitrary code as Local System.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4718

    Last Modified: 16 Apr 2026

    Opera 8.02 and earlier allows remote attackers to cause a denial of service (client crash) via (1) a crafted HTML file with a "content: url(0);" style attribute, a "bodyA" tag, a long string, and a "u" tag with a long attribute, as demonstrated by opera.html; and (2) a BGSOUND element with a "margin:-99;" STYLE attribute.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4726

    Last Modified: 16 Apr 2026

    MUTE 0.4 uses improper flood protection algorithms, which allows remote attackers to obtain sensitive information (privacy leak and search result data) by controlling a drop chain neighbor that is near the end of a message chain.

    Published: 31 Dec 2005
    6.8
    Medium

    CVE-2005-4751

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and WebLogic Express 9.0, 8.1 SP4 and earlier, 7.0 SP6 and earlier, and 6.1 SP7 and earlier allow remote attackers to inject arbitrary web script or HTML and gain administrative privileges via unknown attack vectors.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4763

    Last Modified: 16 Apr 2026

    BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP6 and earlier, and 6.1 SP7 and earlier, when Internet Inter-ORB Protocol (IIOP) is used, sometimes include a password in an exception message that is sent to a client or stored in a log file, which might allow remote attackers to perform unauthorized actions.

    Published: 31 Dec 2005
    7.6
    High

    CVE-2005-4765

    Last Modified: 16 Apr 2026

    BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier and 7.0 SP6 and earlier, when using the weblogic.Deployer command with the t3 protocol, does not use the secure t3s protocol even when an Administration port is enabled on the Administration server, which might allow remote attackers to sniff the connection.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4769

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in addrbook.php in Belchior Foundry vCard PRO 3.1 allows remote attackers to execute arbitrary SQL commands via the addr_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Dec 2005
    6.4
    Medium

    CVE-2005-4772

    Last Modified: 16 Apr 2026

    liby2util in Yet another Setup Tool (YaST) in SUSE Linux before 20051007 preserves permissions and ownerships when copying a remote repository, which might allow local users to read or modify sensitive files, possibly giving local users the ability to exploit CVE-2005-3013.

    Published: 31 Dec 2005
    4
    Medium

    CVE-2005-4786

    Last Modified: 16 Apr 2026

    Buffer overflow in the archive decompression library (vrAZMain.dll 5.8.22.137), as used in HAURI anti-virus products including (1) ViRobot Expert 4.0, (2) ViRobot Advanced Server, and (3) HAURI LiveCall, allows user-assisted attackers to execute arbitrary code via an ALZ archive containing a file with a long filename.

    Published: 31 Dec 2005
    5.1
    Medium

    CVE-2005-4799

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the Homepage field (aka the Website field) in an "image-related comment" and (2) the img_size field in view.php. NOTE: due to lack of details from the researcher, it is not clear whether the comment vector overlaps CVE-2005-1886.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4821

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Land Down Under (LDU) v801 and earlier allow remote attackers to execute arbitrary SQL commands via parameters including (1) the m parameter in auth.php, (2) the f parameter in events.php, or (3) the e parameter in plug.php.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4822

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in projects/project-edit.asp in Digger Solutions Intranet Open Source (IOS) version 2.7.2 allows remote attackers to execute arbitrary SQL commands via the project_id parameter.

    Published: 31 Dec 2005
    5.7
    Medium

    CVE-2005-4825

    Last Modified: 16 Apr 2026

    Cisco Clean Access 3.5.5 and earlier on the Secure Smart Manager allows remote attackers to bypass authentication and cause a denial of service (disk consumption), or make unauthorized files accessible, by uploading files through requests to certain JSP scripts, a related issue to CVE-2005-4332.

    Published: 31 Dec 2005
    6.1
    Medium

    CVE-2005-4826

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(22)EA3 on Catalyst 2950T switches allows remote attackers to cause a denial of service (device reboot) via a crafted Subset-Advert message packet, a different issue than CVE-2006-4774, CVE-2006-4775, and CVE-2006-4776.

    Published: 31 Dec 2005
    4.3
    Medium

    CVE-2005-4833

    Last Modified: 16 Apr 2026

    IBM WebSphere Application Server (WAS) 6.0 before 20050201, when serving pages in an Application WAR or an Extended Document Root, allows remote attackers to obtain the JSP source code and other sensitive information via "a specific JSP URL," related to lack of normalization of the URL format.

    Published: 31 Dec 2005
    7.8
    High

    CVE-2005-4836

    Last Modified: 16 Apr 2026

    The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remote attackers to read JSP source files and obtain sensitive information.

    Published: 31 Dec 2005
    7.8
    High

    CVE-2005-4843

    Last Modified: 16 Apr 2026

    The SmartConnect Class control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4845

    Last Modified: 16 Apr 2026

    The Java Plug-in 1.4.2_03 and 1.4.2_04 controls, and the 1.4.2_03 and 1.4.2_04 <applet> redirector controls, allow remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.

    Published: 31 Dec 2005
    4
    Medium

    CVE-2005-4851

    Last Modified: 16 Apr 2026

    eZ publish 3.4.4 through 3.7 before 20050722 applies certain permissions on the node level, which allows remote authenticated users to bypass the original permissions on embedded objects in XML fields and read these objects.

    Published: 31 Dec 2005