CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2005-4310

    Last Modified: 16 Apr 2026

    SSH Tectia Server 5.0.0 (A, F, and T), when allowing host-based authentication only, allows users to log in with the wrong credentials.

    Published: 17 Dec 2005
    5
    Medium

    CVE-2005-4304

    Last Modified: 16 Apr 2026

    index.php in ezDatabase 2.1.2 and earlier allows remote attackers to obtain sensitive information via an invalid cat_id parameter, which leaks the full pathname in an error message. NOTE: these details are uncertain because the original report has terminology problems and lack of relevant details. The description is based partially on feedback comments.

    Published: 17 Dec 2005
    4.3
    Medium

    CVE-2005-4314

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in ppcal.cgi in PPCal Shopping Cart 3.3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) stop and (2) user parameters.

    Published: 17 Dec 2005
    4.3
    Medium

    CVE-2005-4305

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Edgewall Trac 0.9, 0.9.1, and 0.9.2 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly sanitized before it is returned in an error page.

    Published: 17 Dec 2005
    4.3
    Medium

    CVE-2005-4306

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in SiteNet BBS 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) pg, (2) tid, (3) cid, and (4) fid parameters to netboardr.cgi, or (5) cid parameter to search.cgi.

    Published: 17 Dec 2005
    4.3
    Medium

    CVE-2005-4311

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in DCForum 6.25 and earlier, and possibly DCForum+ 1.x, allows remote attackers to inject arbitrary web script or HTML via (1) the page parameter in dcboard.php and (2) unspecified search parameters.

    Published: 17 Dec 2005
    7.5
    High

    CVE-2005-4315

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the search function in Plexum PLEXCART X3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly involving the (1) s_itemname and (2) s_orderby parameters to plexcart.pl.

    Published: 17 Dec 2005
    5
    Medium

    CVE-2005-4302

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in ezDatabase 2.1.2 and earlier allows remote attackers to include arbitrary local files via ".." sequences in the p parameter.

    Published: 17 Dec 2005
    7.5
    High

    CVE-2005-4303

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php for ezDatabase 2.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the db_id parameter.

    Published: 17 Dec 2005
    7.5
    High

    CVE-2005-4312

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in AlmondSoft Almond Classifieds 5.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 17 Dec 2005
    7.5
    High

    CVE-2005-4313

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in AlmondSoft Almond Personals 4.05 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 17 Dec 2005
    4.3
    Medium

    CVE-2011-3481

    Last Modified: 11 Apr 2025

    The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted References header in an e-mail message.

    Published: 17 Dec 2005
    7.5
    High

    CVE-2005-3652

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Citrix Program Neighborhood client 9.0 and earlier allows remote attackers to execute arbitrary code via a long name value in an Application Set response.

    Published: 16 Dec 2005
    4.3
    Medium

    CVE-2005-4297

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in bbBoard 2.56 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly via the "keys" parameter.

    Published: 16 Dec 2005
    4.3
    Medium

    CVE-2005-4298

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in atl.cgi in AtlantForum 4.02 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) sch_allsubct, (2) before, and (3) ct parameters.

    Published: 16 Dec 2005
    7.5
    High

    CVE-2005-4300

    Last Modified: 16 Apr 2026

    Format string vulnerability in the lire_pop function in pop.c in libremail 1.1.0 and earlier, with compiled with the debug option, allows remote attackers to execute arbitrary code via a crafted e-mail or POP server response.

    Published: 16 Dec 2005
    4.3
    Medium

    CVE-2005-4301

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpXplorer 0.9.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the address bar field.

    Published: 16 Dec 2005
    4.3
    Medium

    CVE-2005-4299

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in atl.cgi in Atlant Pro 4.02 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) before and (2) ct parameters.

    Published: 16 Dec 2005
    4.3
    Medium

    CVE-2005-4277

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in toendaCMS before 0.7 Beta allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 16 Dec 2005
    7.2
    High

    CVE-2005-4278

    Last Modified: 16 Apr 2026

    Untrusted search path vulnerability in Perl before 5.8.7-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.

    Published: 16 Dec 2005
    7.2
    High

    CVE-2005-4279

    Last Modified: 16 Apr 2026

    Untrusted search path vulnerability in Qt-UnixODBC before 3.3.4-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.

    Published: 16 Dec 2005
    7.2
    High

    CVE-2005-4280

    Last Modified: 16 Apr 2026

    Untrusted search path vulnerability in CMake before 2.2.0-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.

    Published: 16 Dec 2005
    4.3
    Medium

    CVE-2005-4281

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Zaygo HostingCart 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via certain search module parameters, possibly the root parameter to zaygo.cgi.

    Published: 16 Dec 2005
    7.5
    High

    CVE-2005-4286

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in PhpLogCon before 1.2.2 allows remote attackers to use arbitrary profiles via unknown vectors involving "'smart' values for userid and password," probably involving an SQL injection vulnerability in the (1) pass and (2) usr parameters in submit.php.

    Published: 16 Dec 2005
    4.3
    Medium

    CVE-2005-4288

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in MarmaraWeb E-commerce allows remote attackers to inject arbitrary web script or HTML via the page parameter to index.php. NOTE: this might be resultant from CVE-2005-4287.

    Published: 16 Dec 2005
    4.3
    Medium

    CVE-2005-4289

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in EDCstore.pl in eDatCat 0.3 allows remote attackers to inject arbitrary web script or HTML via the user_action parameter.

    Published: 16 Dec 2005
    4.3
    Medium

    CVE-2005-4293

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in cp-app.cgi in ClickCartPro (CCP) 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the affl parameter.

    Published: 16 Dec 2005
    4.3
    Medium

    CVE-2005-4294

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Alkacon OpenCms before 6.0.3 allows remote attackers to inject arbitrary web script or HTML via the username in the login page.

    Published: 16 Dec 2005
    4.3
    Medium

    CVE-2005-4295

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE 2.x allows remote attackers to inject arbitrary web script or HTML via the text parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 16 Dec 2005
    7.8
    High

    CVE-2005-4296

    Last Modified: 16 Apr 2026

    AppServ Open Project 2.5.3 allows remote attackers to cause a denial of service via a large HTTP request.

    Published: 16 Dec 2005
    4.3
    Medium

    CVE-2005-4284

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in StaticStore Search Engine 1.189A and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to search.cgi, possibly the keywords parameter. NOTE: this issue was originally disputed by the vendor, but it has since been acknowledged.

    Published: 16 Dec 2005
    7.5
    High

    CVE-2005-4287

    Last Modified: 16 Apr 2026

    PHP remote file include vulnerability in MarmaraWeb E-commerce allows remote attackers to execute arbitrary code via the page parameter to index.php.

    Published: 16 Dec 2005
    4.3
    Medium

    CVE-2005-4291

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in cart.cgi in ECTOOLS Onlineshop 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) product, (2) category, and (3) uid parameters.

    Published: 16 Dec 2005
    7.5
    High

    CVE-2005-3253

    Last Modified: 16 Apr 2026

    Wireless Access Points (AP) for (1) Avaya AP-3 through AP-6 2.5 to 2.5.4, and AP-7/AP-8 2.5 and other versions before 3.1, and (2) Proxim AP-600 and AP-2000 before 2.5.5, and Proxim AP-700 and AP-4000 after 2.4.11 and before 3.1, use a static WEP key of "12345", which allows remote attackers to bypass authentication.

    Published: 16 Dec 2005
    7.8
    High

    CVE-2005-4275

    Last Modified: 16 Apr 2026

    Scientific Atlanta DPX2100 Cable Modem allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LanD), as demonstrated using hping2. NOTE: the provenance of this issue is unknown; the details are obtained solely from third party information.

    Published: 16 Dec 2005
    7.8
    High

    CVE-2005-4276

    Last Modified: 16 Apr 2026

    Westell Versalink 327W allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LanD). NOTE: the provenance of this issue is unknown; the details are obtained solely from third party information.

    Published: 16 Dec 2005
    4.3
    Medium

    CVE-2005-4283

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in The CITY Shop 1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via parameters to the search module, possibly SKey to store.cgi.

    Published: 16 Dec 2005
    4.3
    Medium

    CVE-2005-4285

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in pdestore.cgi in Dick Copits PDEstore 1.8 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the search module parameter or the (2) product and (3) cart_id parameters.

    Published: 16 Dec 2005
    4.3
    Medium

    CVE-2005-4290

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.cgi in ECW-Cart 2.03 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) kword, (2) max, (3) min, (4) comp, and (5) f parameters.

    Published: 16 Dec 2005
    4.3
    Medium

    CVE-2005-4292

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in CommerceSQL 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the keywords parameter in the Quick Find feature.

    Published: 16 Dec 2005
    4.3
    Medium

    CVE-2005-4282

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Zaygo DomainCart 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML, possibly via the root parameter to zaygo.cgi.

    Published: 16 Dec 2005
    5
    Medium

    CVE-2005-4274

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Business Objects WebIntelligence 6.5x allows remote attackers to cause a denial of service (user account lock out) via unknown attack vectors related to "authentication mechanisms" and "form input."

    Published: 15 Dec 2005
    7.2
    High

    CVE-2005-4271

    Last Modified: 16 Apr 2026

    Buffer overflow in the malloc debug system in IBM AIX 5.3 allows local users to execute arbitrary code.

    Published: 15 Dec 2005
    10
    Critical

    CVE-2005-4272

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in IBM AIX 5.1, 5.2, and 5.3 allow remote attackers to execute arbitrary code via (1) muxatmd and (2) slocal.

    Published: 15 Dec 2005
    2.1
    Low

    CVE-2005-4273

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in (1) getShell and (2) getCommand in IBM AIX 5.3 allow local users to append to arbitrary files.

    Published: 15 Dec 2005
    7.8
    High

    CVE-2005-4269

    Last Modified: 16 Apr 2026

    mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a document is reloading, as seen in Microsoft Office InfoPath 2003 by repeatedly clicking the "Delete" button in a repeating section in a form. NOTE: the normal operation of InfoPath appears to involve a local user without any privilege boundaries, so this might not be a vulnerability in InfoPath. If no realistic scenarios exist for this problem in other products, then perhaps it should be excluded from CVE.

    Published: 15 Dec 2005
    7.5
    High

    CVE-2005-4270

    Last Modified: 16 Apr 2026

    Buffer overflow in Watchfire AppScan QA 5.0.609 and 5.0.134 allows remote web servers to execute arbitrary code via an HTTP 401 response with a WWW-Authenticate header containing a long Realm field.

    Published: 15 Dec 2005
    4.3
    Medium

    CVE-2005-4248

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in QuickPayPro 3.1 allow remote attackers to inject arbitrary web script or HTML via various fields, such as those in (1) communication/subscribers.tracking.add.php, (2) support/tickets.add.php, and (3) mycompany/categories.php.

    Published: 15 Dec 2005
    5
    Medium

    CVE-2005-4249

    Last Modified: 16 Apr 2026

    ADP Forum 2.0 through 2.0.3 stores sensitive information in plaintext files under the web document root with insufficient access control, which allows remote attackers to obtain user credentials via requests to the forum/users directory.

    Published: 15 Dec 2005
    4.3
    Medium

    CVE-2005-4253

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in getdox.php in Torrential 1.2 allows remote attackers to inject arbitrary web script or HTML via the URL. NOTE: this might be resultant from CVE-2005-4160.

    Published: 15 Dec 2005