CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2005-3943

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in ilyav FAQ System 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) FAQ_ID and (2) action parameters in (a) viewFAQ.php; and (3) CATEGORY_ID parameter in (b) index.php.

    Published: 1 Dec 2005
    7.8
    High

    CVE-2005-3960

    Last Modified: 16 Apr 2026

    Kadu 0.4.2 and 0.5.0pre allows remote attackers to cause a denial of service (crash or generated traffic) via a malformed message, possibly with incomplete information.

    Published: 1 Dec 2005
    7.5
    High

    CVE-2005-3936

    Last Modified: 16 Apr 2026

    PHP file include vulnerability in SocketKB 1.1.0 and earlier allows remote attackers to include arbitrary local files via the __f parameter.

    Published: 1 Dec 2005
    7.5
    High

    CVE-2005-3939

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in WSN Knowledge Base 1.2.0 and earler allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) perpage, (3) ascdesc, and (4) orderlinks in a displaycat action in (a) index.php; and the (5) id parameter in (b) comments.php and (c) memberlist.php.

    Published: 1 Dec 2005
    7.5
    High

    CVE-2005-3944

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in survey.php in ilyav Survey System 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the SURVEY_ID parameter.

    Published: 1 Dec 2005
    7.8
    High

    CVE-2005-3945

    Last Modified: 16 Apr 2026

    The SynAttackProtect protection in Microsoft Windows 2003 before SP1 and Windows 2000 before SP4 with Update Roll-up uses a hash of predictable data, which allows remote attackers to cause a denial of service (CPU consumption) via a flood of SYN packets that produce identical hash values, which slows down the hash table lookups.

    Published: 1 Dec 2005
    7.5
    High

    CVE-2005-3951

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in survey.php in PHP Labs Survey Wizard allows remote attackers to execute arbitrary SQL commands via the sid parameter.

    Published: 1 Dec 2005
    7.5
    High

    CVE-2005-3952

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in PHP Labs Top Auction allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) type parameters to viewcat.php, or (3) certain search parameters. NOTE: later a disclosure reported the affected version as 1.0.

    Published: 1 Dec 2005
    7.5
    High

    CVE-2005-3953

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Bedeng PSP 1.1 allows remote attackers to execute arbitrary SQL commands via the cwhere parameter to (1) index.php and (2) download.php, or (3) ckode parameter to baca.php.

    Published: 1 Dec 2005
    4.3
    Medium

    CVE-2005-3955

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in MagpieRSS 7.1, as used in (a) blogBuddiesv 0.3, (b) Jaws 0.6.2, and possibly other products, allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to (a) magpie_debug.php and (2) rss_url parameter to (b) magpie_slashbox.php and (c) simple_smarty.php.

    Published: 1 Dec 2005
    7.5
    High

    CVE-2005-3937

    Last Modified: 6 Apr 2026

    SQL injection vulnerability in Softbiz B2B Trading Marketplace Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the cid parameter in (1) selloffers.php, (2) buyoffers.php, (3) products.php, or (4) profiles.php.

    Published: 1 Dec 2005
    7.5
    High

    CVE-2005-3935

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in SocketKB 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) node and (2) art_id parameters.

    Published: 1 Dec 2005
    7.5
    High

    CVE-2005-3941

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in blog.php in Orca Blog 1.3b and earlier allows remote attackers to execute arbitrary SQL commands via the msg parameter.

    Published: 1 Dec 2005
    7.5
    High

    CVE-2005-3942

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in knowledgebase-control.php in Orca Knowledgebase 2.1b and earlier allows remote attackers to execute arbitrary SQL commands via the qid parameter.

    Published: 1 Dec 2005
    6.8
    Medium

    CVE-2005-3950

    Last Modified: 16 Apr 2026

    nuauth in NuFW 1.0.x before 1.0.16 and 1.1 allows authenticated users to cause a denial of service via malformed packets.

    Published: 1 Dec 2005
    7.5
    High

    CVE-2005-2757

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in CoreFoundation in Mac OS X and OS X Server 10.4 through 10.4.3 allows remote attackers to execute arbitrary code via unknown attack vectors involving "validation of URLs."

    Published: 1 Dec 2005
    7.5
    High

    CVE-2005-3705

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in WebKit in Mac OS X and OS X Server 10.3.9 and 10.4.3, as used in applications such as Safari, allows remote attackers to execute arbitrary code via unknown attack vectors.

    Published: 1 Dec 2005
    4.6
    Medium

    CVE-2005-3700

    Last Modified: 16 Apr 2026

    Unknown vulnerability in iodbcadmintool in the ODBC Administrator utility in Mac OS X and OS X Server 10.3.9 and 10.4.3 allows local users to execute arbitrary code via unknown attack vectors.

    Published: 1 Dec 2005
    7.2
    High

    CVE-2005-3701

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in passwordserver in Mac OS X Server 10.3.9 and 10.4.3, when creating an Open Directory master server, allows local users to gain privileges via unknown attack vectors.

    Published: 1 Dec 2005
    5
    Medium

    CVE-2005-3702

    Last Modified: 16 Apr 2026

    Safari in Mac OS X and OS X Server 10.3.9 and 10.4.3 allows remote attackers to cause files to be downloaded to locations outside the download directory via a long file name.

    Published: 1 Dec 2005
    5
    Medium

    CVE-2005-3704

    Last Modified: 16 Apr 2026

    System log server in Mac OS X and OS X Server 10.4 through 10.4.3 allows remote attackers to spoof syslog messages in log files by injecting various control characters such as newline (NL).

    Published: 1 Dec 2005
    4.6
    Medium

    CVE-2005-3962

    Last Modified: 16 Apr 2026

    Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values, which causes an integer wrap and leads to a buffer overflow, as demonstrated using format string vulnerabilities in Perl applications.

    Published: 1 Dec 2005
    7.5
    High

    CVE-2005-3907

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Java Runtime Environment in Java JDK and JRE 5.0 Update 3 and earlier allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary applications via unknown attack vectors involving untrusted Java applets.

    Published: 30 Nov 2005
    4.3
    Medium

    CVE-2005-3908

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in GhostScripter Amazon Shop 5.0.0, and other versions before 5.0.2, allows remote attackers to inject web script or HTML via the query parameter.

    Published: 30 Nov 2005
    7.5
    High

    CVE-2005-3909

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in merchants/index.php in Post Affiliate Pro 2.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the sortorder parameter.

    Published: 30 Nov 2005
    5
    Medium

    CVE-2005-3910

    Last Modified: 16 Apr 2026

    merchants/index.php in Post Affiliate Pro 2.0.4 and earlier, with magic_quotes_gpc disabled, allows remote attackers to include arbitrary local files via the md parameter, possibly due to a directory traversal vulnerability.

    Published: 30 Nov 2005
    7.5
    High

    CVE-2005-3906

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in reflection APIs in Java SDK and JRE 1.4.2_08 and earlier and JDK and JRE 5.0 Update 3 and earlier allow remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary applications via unknown attack vectors, a different set of vulnerabilities than CVE-2005-3905. NOTE: this is associated with the "second and third issues" identified in SUNALERT:102003.

    Published: 30 Nov 2005
    6.4
    Medium

    CVE-2005-3914

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in AFFcommerce 1.1.4 allow remote attackers to execute arbitrary SQL commands via (1) the cl parameter to SubCategory.php and the item_id parameter in (2) ItemInfo.php and (3) ItemReview.php.

    Published: 30 Nov 2005
    7.5
    High

    CVE-2005-3916

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in memberlist.php in WSN Forum 1.21 allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action.

    Published: 30 Nov 2005
    7.5
    High

    CVE-2005-3917

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in usersession in CommodityRentals 2.0 Online Rental Business Creator script allows remote attackers to execute arbitrary SQL commands via the user_id parameter.

    Published: 30 Nov 2005
    7.5
    High

    CVE-2005-3918

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in OvBB 0.08a allow remote attackers to execute arbitrary SQL commands via the (1) threadid parameter to thread.php and (2) userid parameter to profile.php. NOTE: the vendor disputes these issues, saying "these reports are completely unsubstantial.

    Published: 30 Nov 2005
    5
    Medium

    CVE-2005-3923

    Last Modified: 16 Apr 2026

    NetObjects Fusion 9 (NOF9) allows remote attackers to obtain sensitive information, including passwords, by downloading the _versioning_repository_/rollbacklog.xml file, then using it to download and modify the associated ZIP file to edit and republish the site.

    Published: 30 Nov 2005
    7.5
    High

    CVE-2005-3925

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Central Manchester CLC Helpdesk Issue Manager 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) detail[], (2) orderdir, and (3) orderby parameters to find.php, and the (4) id parameter to issue.php.

    Published: 30 Nov 2005
    7.5
    High

    CVE-2005-3924

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in themes/kategorie/index.php in Randshop allows remote attackers to execute arbitrary SQL commands via the (1) kategorieid and (2) katid parameters.

    Published: 30 Nov 2005
    4.6
    Medium

    CVE-2005-3928

    Last Modified: 16 Apr 2026

    Buffer overflow in phgrafx in QNX 6.2.1 and 6.3.0 allows local users to execute arbitrary code via a long command line argument.

    Published: 30 Nov 2005
    5
    Medium

    CVE-2005-3929

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the create function in xarMLSXML2PHPBackend.php in Xaraya 1.0 allows remote attackers to create directories and overwrite arbitrary files via ".." sequences in the module parameter to index.php.

    Published: 30 Nov 2005
    7.5
    High

    CVE-2005-3905

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in reflection APIs in Java SDK and JRE 1.3.1_15 and earlier, 1.4.2_08 and earlier, and JDK and JRE 5.0 Update 3 and earlier allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary application via unknown attack vectors, a different vulnerability than CVE-2005-3906. NOTE: this is associated with the "first issue" identified in SUNALERT:102003.

    Published: 30 Nov 2005
    7.5
    High

    CVE-2005-3904

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Java Management Extensions (JMX) in Java JDK and JRE 5.0 Update 3, 1.4.2 and later, 1.3.1 and later allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary application via unknown attack vectors.

    Published: 30 Nov 2005
    7.5
    High

    CVE-2005-3912

    Last Modified: 16 Apr 2026

    Format string vulnerability in miniserv.pl Perl web server in Webmin before 1.250 and Usermin before 1.180, with syslog logging enabled, allows remote attackers to cause a denial of service (crash or memory consumption) and possibly execute arbitrary code via format string specifiers in the username parameter to the login form, which is ultimately used in a syslog call. NOTE: the code execution might be associated with an issue in Perl.

    Published: 30 Nov 2005
    5
    Medium

    CVE-2005-3913

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the domain alias management in Virtual Hosting Control System (VHCS) 2.4.6.2, related to "creating and deleting forwards for domain aliases," allows users to hijack the forwardings of other users.

    Published: 30 Nov 2005
    7.5
    High

    CVE-2005-3915

    Last Modified: 16 Apr 2026

    The Internet Key Exchange version 1 (IKEv1) implementation in Clavister Client Web allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.

    Published: 30 Nov 2005
    7.5
    High

    CVE-2005-3920

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Babe Logger 2 allows remote attackers to execute arbitrary SQL commands via the (1) gal parameter to index.php or (2) id parameter to comments.php.

    Published: 30 Nov 2005
    2.6
    Low

    CVE-2005-3921

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Cisco IOS Web Server for IOS 12.0(2a) allows remote attackers to inject arbitrary web script or HTML by (1) packets containing HTML that an administrator views via an HTTP interface to the contents of memory buffers, as demonstrated by the URI /level/15/exec/-/buffers/assigned/dump; or (2) sending the router Cisco Discovery Protocol (CDP) packets with HTML payload that an administrator views via the CDP status pages. NOTE: these vectors were originally reported as being associated with the dump and packet options in /level/15/exec/-/show/buffers.

    Published: 30 Nov 2005
    7.5
    High

    CVE-2005-3922

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in pskcmp.dll in Panda Software Antivirus library allows remote attackers to execute arbitrary code via a crafted ZOO archive.

    Published: 30 Nov 2005
    6.4
    Medium

    CVE-2005-3927

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in GuppY 4.5.9 and earlier allow remote attackers to read and include arbitrary files via (1) the meskin parameter to admin/editorTypetool.php, or the lng parameter to the in admin/inc scripts (2) archbatch.php, (3) dbbatch.php, and (4) nwlmail.php.

    Published: 30 Nov 2005
    7.5
    High

    CVE-2005-3911

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in calendar.php in BosDates 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) category parameters.

    Published: 30 Nov 2005
    4.3
    Medium

    CVE-2005-3919

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in PBLang 4.65 allows remote attackers to inject arbitrary web script or HTML via multiple fields in (1) UCP.php and (2) SendPm.php.

    Published: 30 Nov 2005
    7.5
    High

    CVE-2005-3926

    Last Modified: 16 Apr 2026

    Direct static code injection vulnerability in error.php in GuppY 4.5.9 and earlier, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via the _SERVER[REMOTE_ADDR] parameter, which is injected into a .inc script that is later included by the main script.

    Published: 30 Nov 2005
    4.3
    Medium

    CVE-2005-3902

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in gui/errordocs/index.php in Virtual Hosting Control System (VHCS) 2.2.0 through 2.4.6.2 allows remote attackers to inject arbitrary web script or HTML via query strings that are included in an error message, as demonstrated using a parameter containing script.

    Published: 29 Nov 2005
    7.8
    High

    CVE-2005-3901

    Last Modified: 16 Apr 2026

    Macromedia Flash Communication Server MX 1.0 and 1.5 does not sufficiently validate certain RTMP data, which allows attackers to cause a denial of service (instability or crash), as demonstrated using an alpha release build of Flash Player 8.5 (build 133).

    Published: 29 Nov 2005