CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2005-3525

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in an ActiveX control for the installer for Adobe Macromedia Shockwave Player 10.1.0.11 and earlier allows remote attackers to execute arbitrary code via crafted large values for unspecified parameters.

    Published: 31 Dec 2005
    6.5
    Medium

    CVE-2005-3526

    Last Modified: 16 Apr 2026

    Buffer overflow in the IMAP daemon in Ipswitch Collaboration Suite 2006.02 and earlier allows remote authenticated users to execute arbitrary code via a long FETCH command.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-3540

    Last Modified: 16 Apr 2026

    Buffer overflow in petris before 1.0.1 allows remote attackers to execute arbitrary code via unspecified attack vectors.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-3539

    Last Modified: 16 Apr 2026

    Multiple eval injection vulnerabilities in HylaFAX 4.2.3 and earlier allow remote attackers to execute arbitrary commands via (1) the notify script in HylaFAX 4.2.0 to 4.2.3 and (2) crafted CallID parameters to the faxrcvd script in HylaFAX 4.2.2 and 4.2.3.

    Published: 31 Dec 2005
    2.1
    Low

    CVE-2005-3620

    Last Modified: 16 Apr 2026

    The management interface for VMware ESX Server 2.0.x before 2.0.2 patch 1, 2.1.x before 2.1.3 patch 1, and 2.x before 2.5.3 patch 2 records passwords in cleartext in URLs that are stored in world-readable web server log files, which allows local users to gain privileges.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-3627

    Last Modified: 16 Apr 2026

    Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via a DCTDecode stream with (1) a large "number of components" value that is not checked by DCTStream::readBaselineSOF or DCTStream::readProgressiveSOF, (2) a large "Huffman table index" value that is not checked by DCTStream::readHuffmanTables, and (3) certain uses of the scanInfo.numComps value by DCTStream::readScanInfo.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-3658

    Last Modified: 16 Apr 2026

    Multiple heap-based buffer overflows in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.1 and StorEdge Enterprise Backup Software (EBS) 7.1 through 7.2L, allow remote attackers to execute arbitrary code or cause a denial of service (unresponsive application) via malformed RPC packets to (1) RPC program number 390109 (nsrd.exe) and (2) RPC program number 390113 (nsrexecd.exe).

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-3655

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Novell Open Enterprise Server Remote Manager (novell-nrm) in Novell SUSE Linux Enterprise Server 9 allows remote attackers to execute arbitrary code via an HTTP POST request with a negative Content-Length parameter.

    Published: 31 Dec 2005
    6.4
    Medium

    CVE-2005-3706

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in LibSystem in Mac OS X 10.4 through 10.4.5 allows context-dependent attackers to execute arbitrary code by causing an application that uses LibSystem to request a large amount of memory.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-3707

    Last Modified: 16 Apr 2026

    Buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via crafted TGA image files.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-3708

    Last Modified: 16 Apr 2026

    Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via crafted TGA image files.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-3709

    Last Modified: 16 Apr 2026

    Integer underflow in Apple Quicktime before 7.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Color Map Entry Size in a TGA image file.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-3714

    Last Modified: 16 Apr 2026

    The network interface for Apple AirPort Express 6.x before Firmware Update 6.3, and AirPort Extreme 5.x before Firmware Update 5.7, allows remote attackers to cause a denial of service (unresponsive interface) via malformed packets.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4085

    Last Modified: 16 Apr 2026

    Buffer overflow in BlueCoat (a) WinProxy before 6.1a and (b) the web console access functionality in ProxyAV before 2.4.2.3 allows remote attackers to execute arbitrary code via a long Host: header.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4347

    Last Modified: 16 Apr 2026

    The Linux 2.4 kernel patch in kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debian GNU/Linux does not correctly set the "chroot barrier" with util-vserver, which allows attackers to access files on the host system that are outside of the vserver.

    Published: 31 Dec 2005
    Unknown

    CVE-2005-4562

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was assigned in 2005 to an issue that would not be published until 2006, so new identifiers were assigned. Notes: none

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4591

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in bogofilter 0.96.2, 0.95.2, 0.94.14, 0.94.12, and other versions from 0.93.5 to 0.96.2, when using Unicode databases, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via "invalid input sequences" that lead to heap corruption when bogofilter or bogolexer converts character sets.

    Published: 31 Dec 2005
    4.3
    Medium

    CVE-2005-4596

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in read.php in AdesGuestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the totalRows_rsRead parameter.

    Published: 31 Dec 2005
    4.3
    Medium

    CVE-2005-4597

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in iPei Guestbook 1.7 allows remote attackers to inject arbitrary web script or HTML via the email parameter, as used by the email field, when signing a guestbook.

    Published: 31 Dec 2005
    4.3
    Medium

    CVE-2005-4598

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in home.php in OoApp Guestbook 2.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 31 Dec 2005
    4.3
    Medium

    CVE-2005-4603

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in printthread.php in MyBB 1.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a thread message, which is not properly sanitized in the print view of the thread.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4608

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in BugPort 1.147 allows remote attackers to execute arbitrary SQL commands via the (1) devWherePair[0], (2) orderBy, and (3) where parameters.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4609

    Last Modified: 16 Apr 2026

    index.php in BugPort 1.147 and earlier allows remote attackers to obtain sensitive information such as full path and system configuration via an invalid action parameter.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4610

    Last Modified: 16 Apr 2026

    Format string vulnerability in the server for Dopewars before 1.5.12, when running as an NT service, allows remote attackers to execute arbitrary code via unspecified attack vectors.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4611

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search.php in Free ClickBank 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the keywords parameter.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4616

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in iSupport 1.06 allows remote attackers to execute arbitrary SQL commands via the include_file parameter.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4617

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in tickets.php in cSupport 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the pg parameter.

    Published: 31 Dec 2005
    3.6
    Low

    CVE-2005-4618

    Last Modified: 16 Apr 2026

    Buffer overflow in sysctl in the Linux Kernel 2.6 before 2.6.15 allows local users to corrupt user memory and possibly cause a denial of service via a long string, which causes sysctl to write a zero byte outside the buffer. NOTE: since the sysctl is called from a userland program that provides the argument, this might not be a vulnerability, unless a legitimate user-assisted or setuid scenario can be identified.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4619

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in phpoutsourcing Zorum Forum 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the rollid parameter in the showhtmllist method.

    Published: 31 Dec 2005
    4.6
    Medium

    CVE-2005-4620

    Last Modified: 16 Apr 2026

    Buffer overflow in WinRAR 3.50 and earlier allows local users to execute arbitrary code via a long command-line argument. NOTE: because this program executes with the privileges of the invoking user, and because remote programs do not normally have the ability to specify a command-line argument for this program, there may not be a typical attack vector for the issue that crosses privilege boundaries. Therefore this may not be a vulnerability.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4615

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in news.php in DapperDesk 3.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4624

    Last Modified: 16 Apr 2026

    The m_join function in channel.c for PTnet ircd 1.5 and 1.6 allows remote attackers to cause a denial of service (memory exhaustion that triggers a daemon restart) via a large number of requests to join a "charmed channel" such as PTnet, #PTnoticias and #*.log, which causes ircd to open the channel even though it does not have any valid users.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4626

    Last Modified: 16 Apr 2026

    The default configuration of Recruitment Software installs admin/site.xml under the web document root with insufficient access control, which might allow remote attackers to obtain sensitive information (MySQL database credentials) via a direct request.

    Published: 31 Dec 2005
    4.3
    Medium

    CVE-2005-4627

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in (1) GmailSite 1.0 through 1.0.4 and (2) GFHost 0.1.1 through 0.4.2 allows remote attackers to inject arbitrary web script or HTML via the lng parameter.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4628

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in HelpDeskPoint 2.38 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4623

    Last Modified: 16 Apr 2026

    upload.exe in eFileGo 3.01 allows remote attackers to cause a denial of service (CPU consumption) via an argument with an invalid directory name.

    Published: 31 Dec 2005
    4.6
    Medium

    CVE-2005-4636

    Last Modified: 16 Apr 2026

    OpenOffice.org 2.0 and earlier, when hyperlinks has been disabled, does not prevent the user from clicking the WWW-browser button in the Hyperlink dialog, which makes it easier for attackers to trick the user into bypassing intended security settings.

    Published: 31 Dec 2005
    Unknown

    CVE-2005-4633

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-4619. Reason: This candidate is a duplicate of CVE-2005-4619. Notes: All CVE users should reference CVE-2005-4619 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4640

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in class-1 Poll Software 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) pollid or (2) previouspoll parameters.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4641

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in home.php in eazyCMS 2.0 allows remote attackers to execute arbitrary SQL commands via the page_id parameter.

    Published: 31 Dec 2005
    4.3
    Medium

    CVE-2005-4642

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in HydroBB 1.0.0 Beta 2 allow remote attackers to inject arbitrary web script or HTML via the s parameter to (1) search.php, (2) members.php, (3) stats.php, (4) viewforum.php, (5) register.php, (6) usercp.php, (7) groups.php, (8) pms.php, and (9) calendar.php.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4643

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in Antharia OnContent // CMS allows remote attackers to execute arbitrary SQL commands via the pid parameter. NOTE: it is not clear, but this might be an application service provider, in which case it might be excluded from CVE.

    Published: 31 Dec 2005
    4.3
    Medium

    CVE-2005-4644

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the HTML WikiProcessor in Edgewall Trac 0.9.2 allows remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an IMG tag.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4645

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in 3CFR allows remote attackers to execute arbitrary SQL commands via the LangueID parameter.

    Published: 31 Dec 2005
    4.6
    Medium

    CVE-2005-4639

    Last Modified: 16 Apr 2026

    Buffer overflow in the CA-driver (dst_ca.c) for TwinHan DST Frontend/Card in Linux kernel 2.6.12 and other versions before 2.6.15 allows local users to cause a denial of service (crash) and possibly execute arbitrary code by "reading more than 8 bytes into an 8 byte long array".

    Published: 31 Dec 2005
    5.3
    Medium

    CVE-2005-4650

    Last Modified: 16 Apr 2026

    Joomla! 1.03 does not restrict the number of "Search" Mambots, which allows remote attackers to cause a denial of service (resource consumption) via a large number of Search Mambots.

    Published: 31 Dec 2005
    6.4
    Medium

    CVE-2005-4651

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in AlstraSoft EPay Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the pmodule parameter.

    Published: 31 Dec 2005
    6.4
    Medium

    CVE-2005-4652

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in PHlyMail 3.02.01 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4656

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in TClanPortal 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands, and retrieve all usernames and passwords, via the id parameter.

    Published: 31 Dec 2005
    6.8
    Medium

    CVE-2005-4658

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ASP-Programmers.com ASPKnowledgebase allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in the administrative interface.

    Published: 31 Dec 2005