CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2005-3345

    Last Modified: 16 Apr 2026

    rssh 2.0.0 through 2.2.3 allows local users to bypass access restrictions and gain root privileges by using the rssh_chroot_helper command to chroot to an external directory.

    Published: 28 Dec 2005
    7.5
    High

    CVE-2005-4560

    Last Modified: 16 Apr 2026

    The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.

    Published: 28 Dec 2005
    7.8
    High

    CVE-2005-4546

    Last Modified: 16 Apr 2026

    search.php in eggblog 2.0 allows remote attackers to obtain the full path via an invalid q parameter, as used by the Keyword and Search fields, possibly due to an SQL injection vulnerability.

    Published: 28 Dec 2005
    5
    Medium

    CVE-2005-4559

    Last Modified: 16 Apr 2026

    mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly initialize the default_layout and layout_settings variables when an unrecognized HTTP_USER_AGENT string is provided, which allows remote attackers to access arbitrary files via a request with an unrecognized User Agent that also specifies the desired default_layout and layout_settings parameters.

    Published: 28 Dec 2005
    7.5
    High

    CVE-2005-4556

    Last Modified: 16 Apr 2026

    PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, when register_globals is enabled, allows remote attackers to include arbitrary local and remote PHP files via a URL in the (1) lang_settings and (2) language parameters in (a) accounts/inc/include.php and (b) admin/inc/include.php.

    Published: 28 Dec 2005
    7.5
    High

    CVE-2005-4554

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in DEV web management system 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter in an openforum action (openforum.php) in index.php, (2) cat parameter in getfile.php, and (3) target parameter in download_now.php.

    Published: 28 Dec 2005
    4.3
    Medium

    CVE-2005-4549

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Oracle Application Server (OracleAS) Discussion Forum Portlet allows remote attackers to inject arbitrary web script or HTML via the (1) RowKeyValue parameter in the PORTAL schema; and the (2) title and (3) content input fields when creating an forum article.

    Published: 28 Dec 2005
    4.3
    Medium

    CVE-2005-4547

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in home/search.php in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the q parameter, as used by the Keyword and Search fields.

    Published: 28 Dec 2005
    4.3
    Medium

    CVE-2005-4555

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in add.php in DEV web management system 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) ENTER_ARTICLE_TITLE, (2) SPECIFY_ZONE, (3) ENTER_ARTICLE_HEADER, and (4) ENTER_ARTICLE_BODY indices in the language array parameter.

    Published: 28 Dec 2005
    4.3
    Medium

    CVE-2005-4545

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.asp in NetDirect ShopEngine allows remote attackers to inject arbitrary web script or HTML via the EXPS parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 28 Dec 2005
    7.5
    High

    CVE-2005-4548

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the "user area" in RWS Statistics Counter before 2.4.1 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

    Published: 28 Dec 2005
    5
    Medium

    CVE-2005-4550

    Last Modified: 16 Apr 2026

    The PORTAL schema in Oracle Application Server (OracleAS) Discussion Forum Portlet allows remote attackers to obtain the source code for arbitrary JSP and other files via a df_next_page parameter with a trailing null byte (%00).

    Published: 28 Dec 2005
    4.3
    Medium

    CVE-2005-4551

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in sign.php in codegrrl SimpBook 1.0, when html_enable is on, allows remote attackers to inject arbitrary web script or HTML via the message parameter to index.php.

    Published: 28 Dec 2005
    7.2
    High

    CVE-2005-4552

    Last Modified: 16 Apr 2026

    The (1) slsmgr and (2) slsadmin programs in Sun Solaris PC NetLink 2.0 create temporary files insecurely, which allows local users to gain privileges.

    Published: 28 Dec 2005
    7.5
    High

    CVE-2005-4553

    Last Modified: 16 Apr 2026

    Buffer overflow in Golden FTP Server 1.92 allows remote attackers to execute arbitrary code via a long APPE command. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 28 Dec 2005
    5
    Medium

    CVE-2005-4557

    Last Modified: 16 Apr 2026

    dir/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, allows remote attackers to include arbitrary local files via a null byte (%00) in the lang parameter, possibly due to a directory traversal vulnerability.

    Published: 28 Dec 2005
    6.5
    Medium

    CVE-2005-4558

    Last Modified: 16 Apr 2026

    IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for the language parameter to mail/settings.html before it is stored in a database, which can allow remote authenticated users to include arbitrary PHP code via a URL in a modified lang_settings parameter to mail/index.html.

    Published: 28 Dec 2005
    7.5
    High

    CVE-2005-4534

    Last Modified: 16 Apr 2026

    The shadow database feature (syncshadowdb) in Bugzilla 2.9 through 2.16.10 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

    Published: 28 Dec 2005
    7.5
    High

    CVE-2005-4528

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the Chatspot 2.0.0a7 module for phpBB allows remote attackers to execute arbitrary SQL commands via unknown vectors.

    Published: 28 Dec 2005
    7.2
    High

    CVE-2005-4532

    Last Modified: 16 Apr 2026

    scponlyc in scponly 4.1 and earlier, when the operating system supports LD_PRELOAD mechanisms, allows local users to execute arbitrary code with root privileges by creating a chroot directory in their home directory, hard linking to a system setuid application, and using a modified LD_PRELOAD to modify expected function calls in the setuid application.

    Published: 28 Dec 2005
    7.5
    High

    CVE-2005-4529

    Last Modified: 16 Apr 2026

    The Chatspot 2.0.0a7 module for phpBB might allow remote attackers to impersonate other users via unknown vectors.

    Published: 28 Dec 2005
    4.3
    Medium

    CVE-2005-4522

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the view_filters_page.php filters script in Mantis 1.0.0rc3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) view_type and (2) target_field parameters.

    Published: 28 Dec 2005
    5
    Medium

    CVE-2005-4520

    Last Modified: 16 Apr 2026

    Unspecified "port injection" vulnerabilities in filters in Mantis 1.0.0rc3 and earlier have unknown impact and attack vectors. NOTE: due to a lack of relevant details in the vendor changelog, which is the source of this description, it is unclear whether this is a duplicate of another CVE.

    Published: 28 Dec 2005
    7.5
    High

    CVE-2005-4519

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in the manage user page (manage_user_page.php) in Mantis 1.0.0rc3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) prefix and (2) sort parameters to the manage user page (manage_user_page.php), or (3) the sort parameter to view_all_set.php.

    Published: 28 Dec 2005
    7.5
    High

    CVE-2005-4517

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in PHP-Fusion 6.00.200 through 6.00.300 allows remote attackers to execute arbitrary SQL commands via the ratings parameter in multiple scripts, such as ratings_include.php.

    Published: 28 Dec 2005
    5.1
    Medium

    CVE-2005-4530

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft EPay Enterprise 3.0 (formerly DoPays) allow remote attackers to inject arbitrary web script or HTML via multiple unspecified parameters in (1) profile.htm, (2) card.htm, (3) bank.htm, (4) subscriptions.htm, (5) send.htm, (6) request.htm, (7) forgot.htm, (8) escrow.htm, (9) donations.htm, and (10) products.htm.

    Published: 28 Dec 2005
    5
    Medium

    CVE-2005-4521

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in Mantis 1.0.0rc3 and earlier allows remote attackers to modify HTTP headers and conduct HTTP response splitting attacks via (1) the return parameter in login_cookie_test.php and (2) ref parameter in login_select_proj_page.php.

    Published: 28 Dec 2005
    5
    Medium

    CVE-2005-4523

    Last Modified: 16 Apr 2026

    Mantis 1.0.0rc3 and earlier discloses private bugs via public RSS feeds, which allows remote attackers to obtain sensitive information.

    Published: 28 Dec 2005
    5
    Medium

    CVE-2005-4524

    Last Modified: 16 Apr 2026

    Mantis 1.0.0rc3 does not properly handle "Make note private" when a bug is being resolved, which has unknown impact and attack vectors, probably related to an information leak.

    Published: 28 Dec 2005
    4.6
    Medium

    CVE-2005-4525

    Last Modified: 16 Apr 2026

    SmcGui.exe in Sygate Protection Agent 5.0 build 6144 allows local users to obtain management control over the agent by executing the GUI (SmcGui.exe) and then killing the process, which causes the privileged management GUI to launch.

    Published: 28 Dec 2005
    5
    Medium

    CVE-2005-4526

    Last Modified: 16 Apr 2026

    Clearswift MIMEsweeper For Web (a.k.a. WEBsweeper) 4.0 through 5.1 allows remote attackers to bypass filtering via a URL that does not include a .exe extension but returns an executable file.

    Published: 28 Dec 2005
    7.5
    High

    CVE-2005-4527

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Direct News 4.9 allow remote attackers to execute arbitrary SQL commands via (1) the setLang parameter in index.php and (2) unspecified search module parameters.

    Published: 28 Dec 2005
    7.5
    High

    CVE-2005-4533

    Last Modified: 16 Apr 2026

    Argument injection vulnerability in scponlyc in scponly 4.1 and earlier, when both scp and rsync compatibility are enabled, allows local users to execute arbitrary applications via "getopt" style argument specifications, which are not filtered.

    Published: 28 Dec 2005
    Unknown

    CVE-2005-4531

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-3345. Reason: This candidate is a duplicate of CVE-2005-3345. CVE-2005-3345 had already been assigned, but not published, before this candidate was created. Notes: All CVE users should reference CVE-2005-3345 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Dec 2005
    7.5
    High

    CVE-2005-4518

    Last Modified: 16 Apr 2026

    Mantis before 0.19.4 allows remote attackers to bypass the file upload size restriction by modifying the max_file_size parameter to (1) bug_file_add.php, (2) bug_report.php, (3) bug_report_advanced_page.php, and (4) proj_doc_add_page.php.

    Published: 28 Dec 2005
    4.3
    Medium

    CVE-2005-4516

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion 6.00.200 through 6.00.300 allow remote attackers to inject arbitrary web script or HTML via (1) the sortby parameter in members.php and (2) IMG tags.

    Published: 28 Dec 2005
    2.1
    Low

    CVE-2005-3341

    Last Modified: 16 Apr 2026

    DHIS tools DNS package (dhis-tools-dns) before 5.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files created by (1) register-q.sh and (2) register-p.sh.

    Published: 27 Dec 2005
    4.6
    Medium

    CVE-2005-3343

    Last Modified: 16 Apr 2026

    tkdiff before 4.1.1 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

    Published: 27 Dec 2005
    7.5
    High

    CVE-2005-3535

    Last Modified: 16 Apr 2026

    Buffer overflow in KETM 0.0.6 allows local users to execute arbitrary code via unknown vectors.

    Published: 27 Dec 2005
    7.8
    High

    CVE-2005-4585

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the GTP dissector for Ethereal 0.9.1 to 0.10.13 allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.

    Published: 27 Dec 2005
    4.3
    Medium

    CVE-2005-4512

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in WAXTRAPP 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.

    Published: 23 Dec 2005
    7.5
    High

    CVE-2005-4509

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.asp in pTools allows remote attackers to execute arbitrary SQL commands via the docID parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 23 Dec 2005
    7.5
    High

    CVE-2005-4515

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in WebDB 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified search parameters, possibly Search0. NOTE: the vendor has disputed this issue, saying that "WebDB is a generic online database system used by many of the clients of Lois Software. The flaw that was identified was some code that was added for a client to do some testing of his system and only certain safe commands were allowed. This code has now been removed and it is not now possible to use SQL queries as part of the query string. No installation or patch is required All clients use a common code library and have their own front end and databases and connections. So as soon as a change / upgrade / enhancement is made to the code, all users of the software begin to use the latest changes immediately." Since the issue appeared in a custom web site and no action is required on the part of customers, this issue should not be included in CVE

    Published: 23 Dec 2005
    5
    Medium

    CVE-2005-4514

    Last Modified: 16 Apr 2026

    The encapsulation script mechanism in Webwasher CSM Appliance Suite 5.x uses case-sensitive detection of malicious tokens, which allows attackers to bypass script detection by using tokens that can be upper or lower case. NOTE: the vendor has stated that this problem could not be reproduced, and has asked the researcher for more information, without a response as of 20060103

    Published: 23 Dec 2005
    4.3
    Medium

    CVE-2005-4513

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in WANDSOFT e-SEARCH allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the keywords parameter.

    Published: 23 Dec 2005
    4.6
    Medium

    CVE-2005-4511

    Last Modified: 16 Apr 2026

    Format string vulnerability in TN3270 Resource Gateway 1.1.0 allows local users to cause a denial of service and possibly execute arbitrary code via format string specifiers in syslog function calls.

    Published: 23 Dec 2005
    5
    Medium

    CVE-2005-4510

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in server.np in NetPublish Server 7 allows remote attackers to read arbitrary files via "../" sequences in the template parameter.

    Published: 23 Dec 2005
    2.1
    Low

    CVE-2005-4605

    Last Modified: 16 Apr 2026

    The procfs code (proc_misc.c) in Linux 2.6.14.3 and other versions before 2.6.15 allows attackers to read sensitive kernel memory via unspecified vectors in which a signed value is added to an unsigned value.

    Published: 23 Dec 2005
    7.2
    High

    CVE-2005-4505

    Last Modified: 16 Apr 2026

    Unquoted Windows search path vulnerability in McAfee VirusScan Enterprise 8.0i (patch 11) and CMA 3.5 (patch 5) might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run by naPrdMgr.exe when it attempts to execute EntVUtil.EXE under an unquoted "Program Files" path.

    Published: 23 Dec 2005
    4.6
    Medium

    CVE-2005-4506

    Last Modified: 16 Apr 2026

    Nexus Concepts Dev Hound 2.24 and earlier stores username and password information in cleartext in the devhound.tdbd file, which allows local users to gain privileges.

    Published: 23 Dec 2005