CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2005-4000

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in archive.asp in SiteBeater News System 4.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the sKeywords parameter.

    Published: 5 Dec 2005
    4.3
    Medium

    CVE-2005-3998

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.asp in Solupress News 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.

    Published: 5 Dec 2005
    4.3
    Medium

    CVE-2005-3991

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in phpMyChat 0.14.6 allow remote attackers to inject arbitrary web script or HTML via the medium parameter to (1) start_page.css.php and (2) style.css.php; or the From parameter to users_popupL.php.

    Published: 4 Dec 2005
    7.5
    High

    CVE-2005-3992

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in WinEggDropShell remote access trojan (RAT) 1.7 allow remote attackers to execute arbitrary code via (1) a long GET request to the HTTP server, or a long (2) USER or (3) PASS command to the FTP server.

    Published: 4 Dec 2005
    Unknown

    CVE-2005-3990

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-3619. Reason: This candidate is a duplicate of CVE-2006-3619. Notes: All CVE users should reference CVE-2006-3619 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 4 Dec 2005
    7.8
    High

    CVE-2005-3985

    Last Modified: 16 Apr 2026

    The Internet Key Exchange version 1 (IKEv1) implementation in Astaro Security Linux before 6.102 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.

    Published: 4 Dec 2005
    7.5
    High

    CVE-2005-3986

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Instant Photo Gallery 1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter in portfolio.php and (2) cid parameter in content.php.

    Published: 4 Dec 2005
    7.5
    High

    CVE-2005-3987

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Tradesoft CMS allow remote attackers to execute arbitrary SQL commands via unspecified attack vectors.

    Published: 4 Dec 2005
    7.5
    High

    CVE-2005-3988

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in article.php in Pineapple Technologies Lore 1.5.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 4 Dec 2005
    7.8
    High

    CVE-2005-3989

    Last Modified: 16 Apr 2026

    Memory leak in Avaya TN2602AP IP Media Resource 320 circuit pack before vintage 9 firmware allows remote attackers to cause a denial of service (memory consumption) via crafted VoIP packets.

    Published: 4 Dec 2005
    7.5
    High

    CVE-2005-3980

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the ticket query module in Edgewall Trac 0.9 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the group parameter.

    Published: 4 Dec 2005
    7.8
    High

    CVE-2005-3983

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the login page for HP Systems Insight Manager (SIM) 4.0 and 4.1, when accessed by Microsoft Internet Explorer with the MS04-025 patch, leads to a denial of service (browser hang). NOTE: although the advisory is vague, this issue does not appear to involve an attacker at all. If not, then this issue is not a vulnerability.

    Published: 4 Dec 2005
    4.9
    Medium

    CVE-2005-3981

    Last Modified: 16 Apr 2026

    NOTE: this issue has been disputed by third parties. Microsoft Windows XP, 2000, and 2003 allows local users to kill a writable process by using the CreateRemoteThread function with certain arguments on a process that has been opened using the OpenProcess function, possibly involving an invalid address for the start routine. NOTE: followup posts have disputed this issue, saying that if a user already has privileges to write to a process, then other functions could be called or the process could be terminated using PROCESS_TERMINATE

    Published: 4 Dec 2005
    7.5
    High

    CVE-2005-3984

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in WebCalendar 1.0.1 allows remote attackers to execute arbitrary SQL commands via the time_range parameter to edit_report_handler.php. NOTE: the startid/activity_log.php vector is already covered by CVE-2005-3949.

    Published: 4 Dec 2005
    5
    Medium

    CVE-2005-3982

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in layers_toggle.php in WebCalendar 1.0.1 might allow remote attackers to modify HTTP headers and conduct HTTP response splitting attacks via the ret parameter, which is used to redirect URL requests.

    Published: 4 Dec 2005
    4.3
    Medium

    CVE-2005-3966

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.jsp in Java Search Engine (JSE) 0.9.34 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Published: 3 Dec 2005
    4.3
    Medium

    CVE-2005-3971

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the login form in Citrix MetaFrame Secure Access Manager 2.0 through 2.2 and NFuse Elite 1.0 allows remote attackers to inject arbitrary web script or HTML via the username field.

    Published: 3 Dec 2005
    4.3
    Medium

    CVE-2005-3972

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in extremesearch.php in Extreme Search Corporate Edition 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Published: 3 Dec 2005
    6.4
    Medium

    CVE-2005-3974

    Last Modified: 16 Apr 2026

    Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3, when running on PHP5, does not correctly enforce user privileges, which allows remote attackers to bypass the "access user profiles" permission.

    Published: 3 Dec 2005
    7.5
    High

    CVE-2005-3969

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in MXChange before 0.2.0-pre10 PL492 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

    Published: 3 Dec 2005
    5
    Medium

    CVE-2005-3979

    Last Modified: 16 Apr 2026

    relocate_server.php in Coppermine Photo Gallery (CPG) 1.4.2 and 1.4 beta is not removed after installation and does not use authentication, which allows remote attackers to obtain sensitive information, such as database configuration, via a direct request.

    Published: 3 Dec 2005
    7.5
    High

    CVE-2005-3968

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in auth.inc.php in PHPX 3.5.9 and earlier allows remote attackers to execute arbitrary SQL commands, bypass authentication, and upload arbitrary PHP code via the username parameter.

    Published: 3 Dec 2005
    4.3
    Medium

    CVE-2005-3970

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in MXChange before 0.2.0-pre10 PL492 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 3 Dec 2005
    4
    Medium

    CVE-2005-3975

    Last Modified: 16 Apr 2026

    Interpretation conflict in file.inc in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allows remote authenticated users to inject arbitrary web script or HTML via HTML in a file with a GIF or JPEG file extension, which causes the HTML to be executed by a victim who views the file in Internet Explorer as a result of CVE-2005-3312. NOTE: it could be argued that this vulnerability is due to a design flaw in Internet Explorer and the proper fix should be in that browser; if so, then this should not be treated as a vulnerability in Drupal.

    Published: 3 Dec 2005
    7.5
    High

    CVE-2005-3976

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassified 4.2, (4) DUdirectory 3.1 and DUdirectory Pro 3.0 and 3.0 SQL, (5) DUdownload 1.1, (6) DUgallery 3.3, (7) DUnews 1.1, and (8) DUpaypal 3.1 and DUpaypal Pro 3.0, allows remote attackers to execute arbitrary SQL commands via the iType parameter.

    Published: 3 Dec 2005
    4.3
    Medium

    CVE-2005-3977

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in QualityEBiz Quality PPC 1553 allows remote attackers to inject web script or HTML via the REQ parameter to the search module.

    Published: 3 Dec 2005
    7.5
    High

    CVE-2005-3978

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition 1.0.1, Professional Edition 1.5.1, Standard Edition 1.9.6.3, and Free Edition 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter in (a) ViewCat.php and (b) gallery.php, and the (2) ItemNum parameter in (c) ViewItem.php.

    Published: 3 Dec 2005
    4.3
    Medium

    CVE-2005-3967

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the dosearchsite.action module in Atlassian Confluence 2.0.1 Build 321 allows remote attackers to inject arbitrary web script or HTML via the searchQuery.queryString search module parameter.

    Published: 3 Dec 2005
    4.3
    Medium

    CVE-2005-3973

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allow remote attackers to inject arbitrary web script or HTML via various HTML tags and values, such as the (1) legend tag and the value parameter used in (2) label and (3) input tags, possibly due to an incomplete blacklist.

    Published: 3 Dec 2005
    5
    Medium

    CVE-2005-4134

    Last Modified: 16 Apr 2026

    Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to cause a denial of service (CPU consumption and delayed application startup) via a web site with a large title, which is recorded in history.dat but not processed efficiently during startup. NOTE: despite initial reports, the Mozilla vendor does not believe that this issue can be used to trigger a crash or buffer overflow in Firefox. Also, it has been independently reported that Netscape 8.1 does not have this issue.

    Published: 3 Dec 2005
    Unknown

    CVE-2005-3965

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-2607. Reason: This candidate is a duplicate of CVE-2004-2607. Notes: All CVE users should reference CVE-2004-2607 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 2 Dec 2005
    7.5
    High

    CVE-2005-3963

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in session.php in DotClear before 1.2.3 allows remote attackers to execute arbitrary SQL commands via the dc_xd parameter in a cookie.

    Published: 2 Dec 2005
    7.5
    High

    CVE-2005-3964

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in libUil (libUil.so) in OpenMotif 2.2.3, and possibly other versions, allows attackers to execute arbitrary code via the (1) diag_issue_diagnostic function in UilDiags.c and (2) open_source_file function in UilSrcSrc.c.

    Published: 2 Dec 2005
    4.3
    Medium

    CVE-2005-3959

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in FreeWebStat 1.0 rev37 allow remote attackers to inject arbitrary web script or HTML via the (1) site, (2) jsref, (3) jsres, and (4) jscolor parameters to pixel.php, which are not sanitized before being included in the logdb.html file, and (5) the search key to stat.php.

    Published: 1 Dec 2005
    7.5
    High

    CVE-2005-3930

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in N-13 News 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 1 Dec 2005
    7.5
    High

    CVE-2005-3931

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in default.asp in ASP-Rider 1.6 allows remote attackers to execute arbitrary SQL commands via the HTTP referer.

    Published: 1 Dec 2005
    7.5
    High

    CVE-2005-3932

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in okiraku.php in O-Kiraku Nikki 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the day_id parameter.

    Published: 1 Dec 2005
    7.5
    High

    CVE-2005-3933

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in 88Script's Event Calendar 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter.

    Published: 1 Dec 2005
    7.8
    High

    CVE-2005-3934

    Last Modified: 16 Apr 2026

    Buffer overflow in Symantec pcAnywhere 11.0.1, 11.5.1, and all other 32-bit versions allows remote attackers to cause a denial of service (application crash) via unknown attack vectors.

    Published: 1 Dec 2005
    7.5
    High

    CVE-2005-3940

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in ringmaker.php in Orca Ringmaker 2.3c and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter.

    Published: 1 Dec 2005
    5
    Medium

    CVE-2005-3946

    Last Modified: 16 Apr 2026

    Opera 8.50 allows remote attackers to cause a denial of service (crash) via a Java applet with a large string argument to the removeMember JNI method for the com.opera.JSObject class.

    Published: 1 Dec 2005
    5
    Medium

    CVE-2005-3947

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in PHP Upload Center allows remote attackers to read arbitrary files via "../" sequences in the filename parameter.

    Published: 1 Dec 2005
    5
    Medium

    CVE-2005-3948

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in main.php in PHPAlbum 0.2.3 and earlier allows remote attackers to read arbitrary files via the (1) cmd and (2) var1 parameters.

    Published: 1 Dec 2005
    7.5
    High

    CVE-2005-3949

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in WebCalendar 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) startid parameter to activity_log.php, (2) startid parameter to admin_handler.php, (3) template parameter to edit_template.php, and (4) multiple parameters to export_handler.php.

    Published: 1 Dec 2005
    4.3
    Medium

    CVE-2005-3954

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in blogBuddies 0.3 allows remote attackers to inject arbitrary web script or HTML via the u parameter to index.php.

    Published: 1 Dec 2005
    7.5
    High

    CVE-2005-3956

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in DMANews 0.904 and 0.910 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a comments action and the (2) sortorder and (3) display_num parameters in a news_list action.

    Published: 1 Dec 2005
    10
    Critical

    CVE-2005-3957

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors.

    Published: 1 Dec 2005
    7.5
    High

    CVE-2005-3958

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in Entergal MX 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) idcat parameter in a showcat action and (2) the action parameter.

    Published: 1 Dec 2005
    5
    Medium

    CVE-2005-3961

    Last Modified: 16 Apr 2026

    export_handler.php in WebCalendar 1.0.1 allows remote attackers to overwrite WebCalendar data files via a modified id parameter.

    Published: 1 Dec 2005
    7.5
    High

    CVE-2005-3938

    Last Modified: 24 Apr 2026

    SQL injection vulnerability in Softbiz FAQ Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the id parameter in (1) index.php, (2) faq_qanda.php, (3) refer_friend.php, (4) print_article.php, or (5) add_comment.php.

    Published: 1 Dec 2005