CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2005-4659

    Last Modified: 16 Apr 2026

    IPCop (aka IPCop Firewall) before 1.4.10 has world-readable permissions for the backup.key file, which might allow local users to overwrite system configuration files and gain privileges by creating a malicious encrypted backup archive owned by "nobody", then executing ipcoprscfg to restore from this backup.

    Published: 31 Dec 2005
    1.2
    Low

    CVE-2005-4660

    Last Modified: 16 Apr 2026

    Race condition in IPCop (aka IPCop Firewall) before 1.4.10 might allow local users to overwrite system configuration files and gain privileges by replacing a backup archive during the time window when the archive is owned by "nobody" but not yet encrypted, then executing ipcoprscfg to restore from this backup.

    Published: 31 Dec 2005
    4.3
    Medium

    CVE-2005-4663

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in OcoMon 1.20, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4664

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in OcoMon 1.21, and possibly other versions, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the logon page, a different vulnerability than CVE-2005-4662.

    Published: 31 Dec 2005
    4.3
    Medium

    CVE-2005-4665

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in PunBB 1.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via Javascript contained in nested, malformed BBcode url tags.

    Published: 31 Dec 2005
    4.3
    Medium

    CVE-2005-4666

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in PHlyMail before 3.3 Beta1 allows remote attackers to inject arbitrary Javascript via unknown attack vectors.

    Published: 31 Dec 2005
    4.3
    Medium

    CVE-2005-4671

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in simple-upload-53.php in CityPost Simple PHP Upload 5.3 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

    Published: 31 Dec 2005
    4.3
    Medium

    CVE-2005-4672

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in image-editor-52/index.php in CityPost Simple Image-Editor 0.52 allows remote attackers to inject arbitrary web script or HTML via the (1) m1, (2) m2, (3) m3, (4) imgsrc, and (5) m4 parameter.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4673

    Last Modified: 16 Apr 2026

    ioFTPD 0.5.84 u responds with different messages depending on whether or not a username exists, which allows remote attackers to enumerate valid usernames.

    Published: 31 Dec 2005
    7.5
    High

    CVE-2005-4674

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in list.php in Complete PHP Counter allow remote attackers to execute arbitrary SQL commands via the (1) c or (2) s parameter.

    Published: 31 Dec 2005
    4.3
    Medium

    CVE-2005-4675

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in list.php in Complete PHP Counter allows remote attackers to inject arbitrary web script or HTML via the c parameter.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4676

    Last Modified: 16 Apr 2026

    Buffer overflow in Andreas Huggel Exiv2 before 0.9 does not null terminate strings before calling the sscanf function, which allows remote attackers to cause a denial of service (application crash) via images with crafted IPTC metadata.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4680

    Last Modified: 16 Apr 2026

    Sophos Anti-Virus before 4.02, 4.5.x before 4.5.9, 4.6.x before 4.6.9, and 5.x before 5.1.4 allow remote attackers to hide arbitrary files and data via crafted ARJ archives, which are not properly scanned.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4687

    Last Modified: 16 Apr 2026

    PunBB 1.2.9, used alone or with F-ART BLOG:CMS, may trust a client's IP address as specified in the X-Forwarded-For HTTP header rather than the TCP/IP stack, which allows remote attackers to misrepresent their IP address by sending a modified header.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4688

    Last Modified: 16 Apr 2026

    PunBB 1.2.9 does not require password entry when changing the e-mail address in an account's profile, which might allow an attacker to make an address change via a hijacked login session.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4689

    Last Modified: 16 Apr 2026

    Six Apart Movable Type 3.16 stores account names and password hashes in a cookie, which allows remote attackers to login to an account by sniffing the cookie.

    Published: 31 Dec 2005
    2.1
    Low

    CVE-2005-4691

    Last Modified: 16 Apr 2026

    imake in NetBSD before 2.0.3, NetBSD-current before 12 September 2005, certain versions of X.Org, and certain versions of XFree86 allows local users to overwrite arbitrary files via a symlink attack on the temporary file for the file.0 target, which is used for a pre-formatted manual page.

    Published: 31 Dec 2005
    5
    Medium

    CVE-2005-4695

    Last Modified: 16 Apr 2026

    Symantec Brightmail AntiSpam 6.0 build 1 and 2 allows remote attackers to cause a denial of service (bmserver component termination) via malformed MIME messages.

    Published: 31 Dec 2005
    2.1
    Low

    CVE-2005-4696

    Last Modified: 16 Apr 2026

    The Microsoft Wireless Zero Configuration system (WZCS) stores WEP keys and pair-wise Master Keys (PMK) of the WPA pre-shared key in plaintext in memory of the explorer process, which allows attackers with access to process memory to steal the keys and access the network.

    Published: 31 Dec 2005
    2.1
    Low

    CVE-2005-4697

    Last Modified: 16 Apr 2026

    The Microsoft Wireless Zero Configuration system (WZCS) allows local users to access WEP keys and pair-wise Master Keys (PMK) of the WPA pre-shared key via certain calls to the WZCQueryInterface API function in wzcsapi.dll.

    Published: 31 Dec 2005
    4.3
    Medium

    CVE-2005-4698

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in TellMe 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the 91) q_IP (IP) or (2) q_Host (HOST) parameters.

    Published: 31 Dec 2005
    2.1
    Low

    CVE-2005-4701

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Process File System (procfs) in Sun Solaris 10 allows local users to obtain sensitive information such as process working directories via unknown attack vectors, possibly pwdx.

    Published: 31 Dec 2005
    7.8
    High

    CVE-2005-4587

    Last Modified: 16 Apr 2026

    Juniper NetScreen-Security Manager (NSM) 2004 FP2 and FP3 allow remote attackers to cause a denial of service (crash or hang of server components that are automatically restarted) via a long crafted string on (1) port 7800 (the GUI Server port) or (2) port 7801 (the Device Server port).

    Published: 30 Dec 2005
    7.5
    High

    CVE-2005-4586

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in PHPSurveyor before 0.991 allow remote attackers to execute arbitrary SQL commands via the (1) sql parameter in browse.php and the (2) sid, (3) lid, (4) gid, and (5) token parameters in certain PHP scripts.

    Published: 30 Dec 2005
    4.6
    Medium

    CVE-2005-4590

    Last Modified: 16 Apr 2026

    Spb Kiosk Engine 1.0.0.1 allows local users to bypass restrictions on allowed applications via (1) removable media containing a program that will execute because of the autorun setting and (2) applications that are able to invoke other applications, as demonstrated by a file: URL specifying a .exe file.

    Published: 30 Dec 2005
    2.1
    Low

    CVE-2005-4589

    Last Modified: 16 Apr 2026

    Spb Kiosk Engine 1.0.0.1 stores the administrator's passcode in the registry in plaintext, which allows local users to obtain the passcode.

    Published: 30 Dec 2005
    4.3
    Medium

    CVE-2005-4588

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Koobi 5 allows remote attackers to inject arbitrary web script or HTML via nested, malformed url BBCode tags. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 30 Dec 2005
    4.3
    Medium

    CVE-2005-4577

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Hitachi Business Logic - Container (BLC) P-2443-9114 01-00 through 02-06 on Windows, and P-1M43-9111 01-01 through 02-00 on AIX, allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in an unspecified input form.

    Published: 29 Dec 2005
    7.5
    High

    CVE-2005-4569

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in index.fts in FTGate Technology (formerly known as Floosietek) FTGate 4.4 (aka Build 4.4.000 Oct 26 2005) allows remote attackers to execute arbitrary code via a long tzoffset value.

    Published: 29 Dec 2005
    5.8
    Medium

    CVE-2005-4567

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in FTGate Technology (formerly known as Floosietek) FTGate 4.4 (Build 4.4.000 Oct 26 2005) allow remote attackers to inject arbitrary web script or HTML by sending (1) the href parameter to index.fts, or the param1 parameter to (2) /domains/index.fts, (3) /config/licence.fts, or (4) /config/systemacl.fts.

    Published: 29 Dec 2005
    5
    Medium

    CVE-2005-4579

    Last Modified: 16 Apr 2026

    Multiple HTTP response splitting vulnerabilities in Hitachi Business Logic - Container (BLC) P-2443-9114 01-00 through 02-06 on Windows, and P-1M43-9111 01-01 through 02-00 on AIX, allow remote attackers to inject arbitrary HTTP headers via unknown attack vectors in an unspecified input form.

    Published: 29 Dec 2005
    7.5
    High

    CVE-2005-4572

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in myEZshop Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) GroupsId and (2) ItemsId parameters in admin.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 29 Dec 2005
    4.3
    Medium

    CVE-2005-4571

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in myEZshop Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the Keyword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 29 Dec 2005
    7.8
    High

    CVE-2005-4570

    Last Modified: 16 Apr 2026

    The Internet Key Exchange version 1 (IKEv1) implementations in Fortinet FortiOS 2.50, 2.80 and 3.0, FortiClient 2.0,; and FortiManager 2.80 and 3.0 allow remote attackers to cause a denial of service (termination of a process that is automatically restarted) via IKE packets with invalid values of certain IPSec attributes, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the vendor advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.

    Published: 29 Dec 2005
    7.5
    High

    CVE-2005-4568

    Last Modified: 16 Apr 2026

    Multiple format string vulnerabilities in FTGate Technology (formerly known as Floosietek) FTGate 4.4 (aka Build 4.4.000 Oct 26 2005) allow remote attackers to execute arbitrary code via format string specifiers in the (1) USER, (2) PASS, and (3) TOP commands to the POP3 server; and the (4) LIST and (5) AUTHENTICATE commands to the IMAP server.

    Published: 29 Dec 2005
    10
    Critical

    CVE-2005-4565

    Last Modified: 16 Apr 2026

    Format string vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation in ADTRAN NetVanta before 10.03.03.E might allow remote attackers to have an unknown impact via format string specifiers in crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.

    Published: 29 Dec 2005
    7.5
    High

    CVE-2005-4563

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in main.php in Enterprise Heart Enterprise Connector 1.0.2 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the loginid parameter, a different vulnerability than CVE-2005-3875.

    Published: 29 Dec 2005
    4.6
    Medium

    CVE-2005-4581

    Last Modified: 16 Apr 2026

    Buffer overflow in Electric Sheep 2.6.3 client allows local users to execute arbitrary code via a long window-id parameter. NOTE: because the program is not setuid and not normally called from remote programs, there may not be a typical attack vector for the issue that crosses privilege boundaries. Therefore this may not be a vulnerability.

    Published: 29 Dec 2005
    7.5
    High

    CVE-2005-4578

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Hitachi Business Logic - Container (BLC) P-2443-9114 01-00 through 02-06 on Windows, and P-1M43-9111 01-01 through 02-00 on AIX, allow remote attackers to execute arbitrary SQL commands via unknown attack vectors in an unspecified input form.

    Published: 29 Dec 2005
    7.5
    High

    CVE-2005-4573

    Last Modified: 16 Apr 2026

    PHP remote file include vulnerability in plog-admin-functions.php in Plogger Beta 2 allows remote attackers to execute arbitrary code via a URL in the config[basedir] parameter.

    Published: 29 Dec 2005
    4.3
    Medium

    CVE-2005-4574

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in loader.cfm in PaperThin CommonSpot Content Server 4.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the bNewWindow parameter.

    Published: 29 Dec 2005
    5
    Medium

    CVE-2005-4575

    Last Modified: 16 Apr 2026

    PaperThin CommonSpot Content Server 4.5 and earlier allow remote attackers to obtain sensitive information via an invalid errmsg parameter to loader.cfm with a url parameter set to email-login-info.cfm, which leaks the full pathname in the resulting error message.

    Published: 29 Dec 2005
    4.3
    Medium

    CVE-2005-4576

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the UpdateEngine program in Fatwire UpdateEngine 6.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) COUNTRYNAME, (2) EMAIL, and (3) FUELAP_TEMPLATENAME parameters.

    Published: 29 Dec 2005
    4.3
    Medium

    CVE-2005-4580

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Day Communique 4 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search.

    Published: 29 Dec 2005
    7.5
    High

    CVE-2005-4582

    Last Modified: 16 Apr 2026

    Electric Sheep 2.6.3 does not require authentication or integrity checks from the server to the client, which allows remote attackers to download and display arbitrary MPEG movie files via (1) DNS spoofing, (2) a URL on the command line, or (3) a URL in the configuration file. NOTE: the same attack vectors apply to common web browsers that are able to communicate with untrusted web servers, and other problems related to DNS design issues. Therefore this may not be a specific vulnerability. However, a client would reasonably expect to receive content only from the server.

    Published: 29 Dec 2005
    4.3
    Medium

    CVE-2005-4583

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the Management Interface in VMware ESX Server 2.x up to 2.5.x before 24 December 2005 allows "remote code execution in the Web browser" via unspecified attack vectors, probably related to cross-site scripting (XSS).

    Published: 29 Dec 2005
    5
    Medium

    CVE-2005-4584

    Last Modified: 16 Apr 2026

    BZFlag server 2.0.4 and earlier allows remote attackers to cause a denial of service (application crash) via a callsign that is not followed by a NULL (\0) character.

    Published: 29 Dec 2005
    10
    Critical

    CVE-2005-4566

    Last Modified: 16 Apr 2026

    Buffer overflow in the Internet Key Exchange version 1 (IKEv1) implementation in ADTRAN NetVanta before 10.03.03.E might allow remote attackers to have an unknown impact via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.

    Published: 29 Dec 2005
    5
    Medium

    CVE-2005-4564

    Last Modified: 16 Apr 2026

    The Internet Key Exchange version 1 (IKEv1) implementation in ADTRAN NetVanta before 10.03.03.E might allow remote attackers to cause a denial of service via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.

    Published: 29 Dec 2005
    7.5
    High

    CVE-2005-4601

    Last Modified: 16 Apr 2026

    The delegate code in ImageMagick 6.2.4.5-0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename that is processed by the display command.

    Published: 29 Dec 2005