CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2005-4859

    Last Modified: 16 Apr 2026

    mimicboard2 (Mimic2) 086 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mimic2.dat.

    Published: 31 Dec 2005
    9.3
    Critical

    CVE-2005-4867

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the SATENCRYPT function in IBM DB2 8.1, when Satellite Administration (SATADMIN) is enabled, allows remote attackers to execute arbitrary code via a long parameter.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-1753

    Last Modified: 16 Apr 2026

    ReadMessage.jsp in JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to view other users' e-mail attachments via a direct request to /mailboxesdir/username@domainname. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-0038

    Last Modified: 16 Apr 2026

    The DNS implementation of PowerDNS 2.9.16 and earlier allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.

    Published: 31 Dec 2005
    9.3
    Critical

    CVE-2005-1924

    Last Modified: 16 Apr 2026

    The G/PGP (GPG) Plugin 2.1 and earlier for Squirrelmail allow remote authenticated users to execute arbitrary commands via shell metacharacters in (1) the fpr parameter to the deleteKey function in gpg_keyring.php, as called by (a) import_key_file.php, (b) import_key_text.php, and (c) keyring_main.php; and (2) the keyserver parameter to the gpg_recv_key function in gpg_key_functions.php, as called by gpg_options.php. NOTE: this issue may overlap CVE-2007-3636.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-2194

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the Apple Mac OS X kernel before 10.4.2 allows remote attackers to cause a denial of service (kernel panic) via a crafted TCP packet, possibly related to source routing or loose source routing.

    Published: 31 Dec 2005
    2.6
    Low

    CVE-2005-2343

    Last Modified: 16 Apr 2026

    Research in Motion (RIM) BlackBerry Handheld web browser for BlackBerry Handheld before 4.0.2 allows remote attackers to cause a denial of service (hang) via a Java Application Description (JAD) file with a long application name and vendor string, which prevents a browser dialog from being properly dismissed.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-2344

    Last Modified: 16 Apr 2026

    The BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.0 to version 4.0 Service Pack 2 allows attackers to cause a denial of service via a malformed Portable Network Graphics (PNG) file that triggers a heap-based buffer overflow.

    Published: 31 Dec 2005
    6.4
    Medium

    CVE-2005-2463

    Last Modified: 16 Apr 2026

    Kayako liveResponse 2.x allows remote attackers to obtain sensitive information via a direct request to addressbook.php and other include scripts, which reveals the path in an error message.

    Published: 31 Dec 2005
    5.8
    Medium

    CVE-2005-2467

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to view.php, (2) release parameter to list.php, or (3) F parameter to get_jsrs_data.php.

    Published: 31 Dec 2005
    6.4
    Medium

    CVE-2005-2468

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) isCorrectPassword or (2) userExist function in class.auth.php, getCustomFieldReport function in (4) custom_fields.php, (5) custom_fields_graph.php, or (6) class.report.php, or the insert function in (7) releases.php or (8) class.release.php.

    Published: 31 Dec 2005
    1.2
    Low

    CVE-2005-2527

    Last Modified: 16 Apr 2026

    Race condition in Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X allows local users to corrupt files or create arbitrary files via unspecified attack vectors related to a temporary directory, possibly due to a symlink attack.

    Published: 31 Dec 2005
    10
    Critical

    CVE-2005-2529

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X allows local users to gain privileges via unspecified attack vectors relating to "the utility used to update Java shared archives."

    Published: 31 Dec 2005
    9.3
    Critical

    CVE-2005-2618

    Last Modified: 16 Apr 2026

    Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allow remote attackers to execute arbitrary code via (1) a UUE file containing an encoded file with a long filename handled by uudrdr.dll, (2) a compressed ZIP file with a long filename handled by kvarcve.dll, (3) a TAR archive with a long filename that is extracted to a directory with a long path handled by the TAR reader (tarrdr.dll), (4) an email that contains a long HTTP, FTP, or // link handled by the HTML speed reader (htmsr.dll) or (5) an email containing a crafted long link handled by the HTML speed reader (htmsr.dll).

    Published: 31 Dec 2005
    7.2
    High

    CVE-2005-2711

    Last Modified: 16 Apr 2026

    ISS BlackIce 3.6, as used in multiple products including BlackICE PC Protection, Server Protection, Agent for Server, and RealSecure Desktop 3.6 and 7.0, does not drop privileges before launching help from the "More Info" button in the "Application Protection" dialog, which allows local users to execute arbitrary programs as SYSTEM.

    Published: 31 Dec 2005
    6.8
    Medium

    CVE-2005-2713

    Last Modified: 16 Apr 2026

    passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local users to create arbitrary world-writable files as root by specifying an alternate file in the password database option.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-2738

    Last Modified: 16 Apr 2026

    Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X does not prevent multiple programs from opening the same port as a Java ServerSocket, which allows local users to operate a Java program that intercepts network data intended for the ServerSocket of a different Java program.

    Published: 31 Dec 2005
    9.3
    Critical

    CVE-2005-2922

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, and Helix Player allows remote malicious servers to cause a denial of service (crash) and possibly execute arbitrary code via a chunked Transfer-Encoding HTTP response in which either (1) the chunk header length is specified as -1, (2) the chunk header with a length that is less than the actual amount of sent data, or (3) a missing chunk header.

    Published: 31 Dec 2005
    1.9
    Low

    CVE-2005-3126

    Last Modified: 16 Apr 2026

    The (1) kantiword (kantiword.sh) and (2) gantiword (gantiword.sh) scripts in antiword 0.35 and earlier allow local users to overwrite arbitrary files via a symlink attack on temporary (a) output and (b) error files.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-3187

    Last Modified: 16 Apr 2026

    The listening daemon in Blue Coat Systems Inc. WinProxy before 6.1a allows remote attackers to cause a denial of service (crash) via a long HTTP request that causes an out-of-bounds read.

    Published: 31 Dec 2005
    7.2
    High

    CVE-2005-3340

    Last Modified: 16 Apr 2026

    The tuxpaint-import.sh script in Tux Paint (tuxpaint) 0.9.14 and earlier creates temporary files insecurely, with unknown impact and attack vectors.

    Published: 31 Dec 2005
    2.1
    Low

    CVE-2005-3356

    Last Modified: 16 Apr 2026

    The mq_open system call in Linux kernel 2.6.9, in certain situations, can decrement a counter twice ("double decrement") as a result of multiple calls to the mntput function when the dentry_open function call fails, which allows local users to cause a denial of service (panic) via unspecified attack vectors.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-3538

    Last Modified: 16 Apr 2026

    hfaxd in HylaFAX 4.2.3, when PAM support is disabled, accepts arbitrary passwords, which allows remote attackers to gain privileges.

    Published: 31 Dec 2005
    7.6
    High

    CVE-2005-3618

    Last Modified: 16 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the management interface for VMware ESX Server 2.0.x before 2.0.2 patch 1, 2.1.x before 2.1.3 patch 1, and 2.x before 2.5.3 patch 2 allows allows remote attackers to perform unauthorized actions as the administrator via URLs, as demonstrated using the setUsr operation to change a password. NOTE: this issue can be leveraged with CVE-2005-3619 to automatically perform the attacks.

    Published: 31 Dec 2005
    6.8
    Medium

    CVE-2005-3619

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the management interface for VMware ESX 2.5.x before 2.5.2 upgrade patch 2, 2.1.x before 2.1.2 upgrade patch 6, and 2.0.x before 2.0.1 upgrade patch 6 allows remote attackers to inject arbitrary web script or HTML via messages that are not sanitized when viewing syslog log files.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-3624

    Last Modified: 16 Apr 2026

    The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-3626

    Last Modified: 16 Apr 2026

    Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-3630

    Last Modified: 16 Apr 2026

    Fedora Directory Server before 10 allows remote attackers to obtain sensitive information, such as the password from adm.conf via an IFRAME element, probably involving an Apache httpd.conf configuration that orders "allow" directives before "deny" directives.

    Published: 31 Dec 2005
    10
    Critical

    CVE-2005-3653

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field.

    Published: 31 Dec 2005
    10
    Critical

    CVE-2005-3656

    Last Modified: 16 Apr 2026

    Multiple format string vulnerabilities in logging functions in mod_auth_pgsql before 2.0.3, when used for user authentication against a PostgreSQL database, allows remote unauthenticated attackers to execute arbitrary code, as demonstrated via the username.

    Published: 31 Dec 2005
    6.5
    Medium

    CVE-2005-3712

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in rsync in Mac OS X 10.4 through 10.4.5 allows remote authenticated users to execute arbitrary code via long extended attributes.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-3713

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a GIF image file with a crafted Netscape Navigator Application Extension Block that modifies the heap in the Picture Modifier block.

    Published: 31 Dec 2005
    2.1
    Low

    CVE-2005-3782

    Last Modified: 16 Apr 2026

    Mac OS X 10.4.3 up to 10.4.6, when loginwindow uses the "Name and password" setting, and the "Show the Restart, Sleep, and Shut Down buttons" option is disabled, allows users with physical access to bypass login and reboot the system by entering ">restart", ">power", or ">shutdown" sequences after the username.

    Published: 31 Dec 2005
    2.1
    Low

    CVE-2005-4352

    Last Modified: 16 Apr 2026

    The securelevels implementation in NetBSD 2.1 and earlier, and Linux 2.6.15 and earlier, allows local users to bypass time setting restrictions and set the clock backwards by setting the clock ahead to the maximum unixtime value (19 Jan 2038), which then wraps around to the minimum value (13 Dec 1901), which can then be set ahead to the desired time, aka "settimeofday() time wrap."

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4418

    Last Modified: 16 Apr 2026

    util-vserver before 0.30.208-1 with kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debian GNU/Linux sets a default policy that trusts unknown capabilities, which could allow local users to conduct unauthorized activities.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4593

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in phpDocumentor 1.3.0 rc4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary code via a URL in the (1) FORUM[LIB] parameter in Documentation/tests/bug-559668.php and (2) the root_dir parameter in docbuilder/file_dialog.php.

    Published: 31 Dec 2005
    7.2
    High

    CVE-2005-4595

    Last Modified: 16 Apr 2026

    Untrusted search path vulnerability (RPATH) in XnView 1.70 and NView 4.51 on Gentoo Linux allows local users to execute arbitrary code via a malicious library in the current working directory.

    Published: 31 Dec 2005
    6.4
    Medium

    CVE-2005-4600

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to read or include arbitrary files via a trailing null byte (%00) in the (1) theme, (2) language, (3) plugins, or (4) lang parameter.

    Published: 31 Dec 2005
    10
    Critical

    CVE-2005-4604

    Last Modified: 16 Apr 2026

    Buffer overflow in MTink in the printer-filters-utils package allows local users to execute arbitrary code via a long HOME environment variable.

    Published: 31 Dec 2005
    4.3
    Medium

    CVE-2005-4607

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in BugPort 1.147 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) ids[0], (2) action, (3) report_id, (4) devWherePair[1][1], and (5) binds[0] parameters.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4612

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in VUBB alpha rc1 allow remote attackers to execute arbitrary SQL commands via the (1) f parameter to viewforum.php, (2) t parameter to viewtopic.php, and (3) view parameter to usercp.php.

    Published: 31 Dec 2005
    7.1
    High

    CVE-2005-4625

    Last Modified: 16 Apr 2026

    Drivers for certain display adapters, including (1) an unspecified ATI driver and (2) an unspecified Intel driver, might allow remote attackers to cause a denial of service (system crash) via a large JPEG image, as demonstrated in Internet Explorer using stoopid.jpg with a width and height of 9999999.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4629

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in SMBCMS 2.1 allows remote attackers to execute arbitrary SQL commands via unspecified search parameters.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4631

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in Zina 0.12.07 and earlier allows remote attackers to execute arbitrary SQL commands via the p parameter.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4632

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in poll_frame.php in Vote! Pro 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the poll_id parameter.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4634

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in ActiveCampaign SupportTrio 1.4 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the provenance of this information is unknown because the source URL is not available; the details are obtained solely from third party information.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4635

    Last Modified: 16 Apr 2026

    The nl_fib_input function in fib_frontend.c in the Linux kernel before 2.6.15 does not check for valid lengths of the header and payload, which allows remote attackers to cause a denial of service (invalid memory reference) via malformed fib_lookup netlink messages.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4646

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in index.php in PEARLINGER Pearl Forums 2.4 allows remote attackers to include arbitrary files via the mode parameter, possibly due to a directory traversal vulnerability. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4647

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in PEARLINGER Pearl Forums 2.4 allow remote attackers to execute arbitrary SQL commands via the (1) forumsId and (2) topicId parameters in index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Dec 2005
    4.3
    Medium

    CVE-2005-4649

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Advanced Guestbook 2.2 and 2.3.1 allow remote attackers to inject arbitrary web script or HTML via (1) the entry parameter in index.php and (2) the gb_id parameter in comment.php. NOTE: The index.php/entry vector might be resultant from CVE-2005-1548.

    Published: 31 Dec 2005