CVE Feed

    Dashboard / CVE

    3.5
    Low

    CVE-2005-4855

    Last Modified: 16 Apr 2026

    Unrestricted file upload vulnerability in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050922 does not restrict Image datatype uploads to image content types, which allows remote authenticated users to upload certain types of files, as demonstrated by .js files, which may enable cross-site scripting (XSS) attacks or other attacks.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4856

    Last Modified: 16 Apr 2026

    The admin interface in eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051110 does not properly handle authorization errors, which allows remote attackers to obtain sensitive information and see the admin pagelayout and associated templates via a request with (1) "anything after the url" or (2) a "wrong url".

    Published: 31 Dec 2005
    4
    Medium

    CVE-2005-4857

    Last Modified: 16 Apr 2026

    eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051128 allows remote authenticated users to cause a denial of service (Apache httpd segmentation fault) via a request to content/advancedsearch.php with an empty SearchContentClassID parameter, reportedly related to a "memory addressing error".

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4862

    Last Modified: 16 Apr 2026

    The search functionality in XWiki 0.9.793 indexes cleartext user passwords, which allows remote attackers to obtain sensitive information via a search string that matches a password.

    Published: 31 Dec 2005
    7.2
    High

    CVE-2005-4863

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in db2fmp in IBM DB2 7.x and 8.1 allows local users to execute arbitrary code via a long parameter.

    Published: 31 Dec 2005
    7.2
    High

    CVE-2005-4864

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in libdb2.so in IBM DB2 7.x and 8.1 allows local users to execute arbitrary code via a long DB2LPORT environment variable.

    Published: 31 Dec 2005
    10
    Critical

    CVE-2005-4865

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in call in IBM DB2 7.x and 8.1 allows remote attackers to execute arbitrary code via a long libname.

    Published: 31 Dec 2005
    2.1
    Low

    CVE-2005-4869

    Last Modified: 16 Apr 2026

    The (1) to_char and (2) to_date function in IBM DB2 8.1 allows local users to cause a denial of service (application crash) via an empty string in the second parameter, which causes a null pointer dereference.

    Published: 31 Dec 2005
    4.3
    Medium

    CVE-2005-4870

    Last Modified: 16 Apr 2026

    Stack-based buffer overflows in the (1) xmlvarcharfromfile, (2) xmlclobfromfile, (3) xmlfilefromvarchar, and (4) xmlfilefromclob function calls in IBM DB2 8.1 allow remote attackers to execute arbitrary code via a 94-byte second argument, which causes the return address to be overwritten with a pointer to the argument.

    Published: 31 Dec 2005
    4.3
    Medium

    CVE-2005-4871

    Last Modified: 16 Apr 2026

    Certain XML functions in IBM DB2 8.1 run with the privileges of DB2 instead of the logged-in user, which allows remote attackers to create or overwrite files via (1) XMLFileFromVarchar or (2) XMLFileFromClob, or read files via (3) XMLVarcharFromFile or (4) XMLClobFromFile.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4873

    Last Modified: 16 Apr 2026

    Multiple stack-based buffer overflows in the phpcups PHP module for CUPS 1.1.23rc1 might allow context-dependent attackers to execute arbitrary code via vectors that result in long function parameters, as demonstrated by the cups_get_dest_options function in phpcups.c.

    Published: 31 Dec 2005
    9.3
    Critical

    CVE-2005-1730

    Last Modified: 16 Apr 2026

    Multiple vulnerabilities in the OpenSSL ASN.1 parser, as used in Novell iManager 2.0.2, allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted packets, as demonstrated by "OpenSSL ASN.1 brute forcer." NOTE: this issue might overlap CVE-2004-0079, CVE-2004-0081, or CVE-2004-0112.

    Published: 31 Dec 2005
    2.1
    Low

    CVE-2005-2462

    Last Modified: 16 Apr 2026

    Kayako liveResponse 2.x, when logging in a user, records the password in plaintext in the URL, which allows local users and possibly remote attackers to gain privileges.

    Published: 31 Dec 2005
    9.3
    Critical

    CVE-2005-2619

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in kvarcve.dll in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allows remote attackers to delete arbitrary files via a (1) ZIP, (2) UUE or (3) TAR archive that contains a .. (dot dot) in the filename, which is not properly handled when generating a preview.

    Published: 31 Dec 2005
    Unknown

    CVE-2005-3597

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-3573. Reason: This candidate is a duplicate of CVE-2005-3573. A CNA error by MITRE introduced the duplicate. Notes: All CVE users should reference CVE-2005-3573 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 Dec 2005
    10
    Critical

    CVE-2005-3625

    Last Modified: 16 Apr 2026

    Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-3654

    Last Modified: 16 Apr 2026

    Blue Coat Systems Inc. WinProxy before 6.1a allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of packets with 0xFF characters to the Telnet port (TCP 23), which corrupts the heap.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-3710

    Last Modified: 16 Apr 2026

    Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a TIFF image file with modified image height and width (ImageWidth) tags.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-3711

    Last Modified: 16 Apr 2026

    Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a TIFF image file with modified (1) "strips" (StripByteCounts) or (2) "bands" (StripOffsets) values.

    Published: 31 Dec 2005
    4.3
    Medium

    CVE-2005-4351

    Last Modified: 16 Apr 2026

    The securelevels implementation in FreeBSD 7.0 and earlier, OpenBSD up to 3.8, DragonFly up to 1.2, and Linux up to 2.6.15 allows root users to bypass immutable settings for files by mounting another filesystem that masks the immutable files while the system is running.

    Published: 31 Dec 2005
    Unknown

    CVE-2005-4561

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was assigned in 2005 to an issue that would not be published until 2006, so new identifiers were assigned. Notes: none

    Published: 31 Dec 2005
    2.1
    Low

    CVE-2005-0985

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the Mac OS X kernel before 10.3.8 allows local users to cause a denial of service (temporary hang) via unspecified attack vectors related to the fan control unit (FCU) driver.

    Published: 31 Dec 2005
    7.2
    High

    CVE-2005-1528

    Last Modified: 16 Apr 2026

    Untrusted search path vulnerability in the crttrap command in QNX Neutrino RTOS 6.2.1 allows local users to load arbitrary libraries via a LD_LIBRARY_PATH environment variable that references a malicious library.

    Published: 31 Dec 2005
    4.6
    Medium

    CVE-2005-1726

    Last Modified: 16 Apr 2026

    The CoreGraphics Window Server in Mac OS X 10.4.1 allows local users with console access to gain privileges by "launching commands into root sessions."

    Published: 31 Dec 2005
    6.4
    Medium

    CVE-2005-1752

    Last Modified: 16 Apr 2026

    viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file_name parameter.

    Published: 31 Dec 2005
    6.4
    Medium

    CVE-2005-1755

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in poll_vote.php in PHP Poll Creator 1.01 allows remote attackers to execute arbitrary PHP code via the relativer_pfad parameter.

    Published: 31 Dec 2005
    Unknown

    CVE-2005-1919

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 31 Dec 2005
    1.7
    Low

    CVE-2005-1976

    Last Modified: 16 Apr 2026

    Novell NetMail 3.5.2a, 3.5.2b, and 3.5.2c, when running on Linux, sets the owner and group ID to 500 for certain files, which could allow users or groups with that ID to execute arbitrary code or cause a denial of service by modifying those files.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-2315

    Last Modified: 16 Apr 2026

    Buffer overflow in Domain Name Relay Daemon (DNRD) before 2.19.1 allows remote attackers to execute arbitrary code via a large number of large DNS packets with the Z and QR flags cleared.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-2316

    Last Modified: 16 Apr 2026

    Domain Name Relay Daemon (DNRD) before 2.19.1 allows remote attackers to cause a denial of service (infinite recursion) via a DNS packet that uses message compression in the QNAME and two pointers that point to each other (circular buffer).

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-2340

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a crafted (1) QuickTime Image File (QTIF), (2) PICT, or (3) JPEG format image with a long data field.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-2341

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Research in Motion (RIM) BlackBerry Attachment Service allows remote attackers to cause a denial of service (hang) via an e-mail attachment with a crafted TIFF file.

    Published: 31 Dec 2005
    7.8
    High

    CVE-2005-2342

    Last Modified: 16 Apr 2026

    Research in Motion (RIM) BlackBerry Router allows remote attackers to cause a denial of service (communication disruption) via crafted Server Routing Protocol (SRP) packets.

    Published: 31 Dec 2005
    4.6
    Medium

    CVE-2005-2454

    Last Modified: 16 Apr 2026

    IBM Lotus Notes 6.5.4 and 6.5.5, and 7.0.0 and 7.0.1, uses insecure default permissions (Everyone/Full Control) for the "Notes" folder and all children, which allows local users to gain privileges and modify, add, or delete files in that folder.

    Published: 31 Dec 2005
    5.8
    Medium

    CVE-2005-2460

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Kayako liveResponse 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter or (2) name field when entering a session or sending a message.

    Published: 31 Dec 2005
    6.4
    Medium

    CVE-2005-2461

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in the calendar feature in Kayako liveResponse 2.x allow remote attackers to execute arbitrary SQL commands via the (1) year or (2) date parameter.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-2464

    Last Modified: 16 Apr 2026

    login.php in PCXP/TOPPE CMS allows remote attackers to bypass authentication and gain privileges by modifying the cookie to match the target userid.

    Published: 31 Dec 2005
    5.8
    Medium

    CVE-2005-2465

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in pm.php in PCXP/TOPPE CMS allows remote attackers to inject arbitrary web script or HTML via the msg variable.

    Published: 31 Dec 2005
    6.4
    Medium

    CVE-2005-2466

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in the auth_user function in admin.php in OpenBook 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.

    Published: 31 Dec 2005
    10
    Critical

    CVE-2005-2530

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Java 1.3.1 before 1.3.1_16 on Apple Mac OS X allows an untrusted applet to gain privileges, related to "Mac OS X specific extensions."

    Published: 31 Dec 2005
    7.8
    High

    CVE-2005-2712

    Last Modified: 16 Apr 2026

    The LDAP server (nldap.exe) in IBM Lotus Domino before 7.0.1, 6.5.5, and 6.5.4 FP2 allows remote attackers to cause a denial of service (crash) via a long bind request, which triggers a null dereference.

    Published: 31 Dec 2005
    6.8
    Medium

    CVE-2005-2714

    Last Modified: 16 Apr 2026

    passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local users to overwrite arbitrary files via a symlink attack on the .pwtmp.[PID] temporary file.

    Published: 31 Dec 2005
    2.1
    Low

    CVE-2005-2762

    Last Modified: 16 Apr 2026

    Avaya VPNRemote before 4.2.33 stores credentials in cleartext in process memory, which allows attackers to obtain the VPN user's credentials.

    Published: 31 Dec 2005
    7.2
    High

    CVE-2005-2932

    Last Modified: 16 Apr 2026

    Multiple Check Point Zone Labs ZoneAlarm products before 7.0.362, including ZoneAlarm Security Suite 5.5.062.004 and 6.5.737, use insecure default permissions for critical files, which allows local users to gain privileges or bypass security controls.

    Published: 31 Dec 2005
    7.2
    High

    CVE-2005-2934

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in ptrace in SCO UnixWare 7.1.3 and 7.1.4 allows local users to gain privileges via unspecified vectors.

    Published: 31 Dec 2005
    10
    Critical

    CVE-2005-3057

    Last Modified: 16 Apr 2026

    The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and other versions before 3.0 MR1, allows remote attackers to bypass the Fortinet FTP anti-virus engine by sending a STOR command and uploading a file before the FTP server response has been sent, as demonstrated using LFTP.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-3058

    Last Modified: 16 Apr 2026

    Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HTTP request terminated with a line feed (LF) and not carriage return line feed (CRLF) or (2) HTTP request with no Host field, which is still processed by most web servers without violating RFC2616.

    Published: 31 Dec 2005
    7.6
    High

    CVE-2005-3188

    Last Modified: 16 Apr 2026

    Buffer overflow in Nullsoft Winamp 5.094 allows remote attackers to execute arbitrary code via (1) an m3u file containing a long line ending in .wma or (2) a pls file containing a long File1 value ending in .wma, a different vulnerability than CVE-2006-0476.

    Published: 31 Dec 2005
    5.1
    Medium

    CVE-2005-3240

    Last Modified: 16 Apr 2026

    Race condition in Microsoft Internet Explorer allows user-assisted attackers to overwrite arbitrary files and possibly execute code by tricking a user into performing a drag-and-drop action from certain objects, such as file objects within a folder view, then predicting the drag action, and re-focusing to a malicious window.

    Published: 31 Dec 2005
    1.2
    Low

    CVE-2005-3342

    Last Modified: 16 Apr 2026

    noweb 2.10c and earlier allows local users to overwrite arbitrary files via symlink attacks on temporary files in (1) lib/toascii.nw and (2) shell/roff.mm.

    Published: 31 Dec 2005