CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2005-3900

    Last Modified: 16 Apr 2026

    Macromedia Breeze Communication Server and Breeze Live Server does 5.1 and earlier not sufficiently validate certain RTMP data, which allows attackers to cause a denial of service (instability or crash), as demonstrated using an alpha release build of Flash Player 8.5 (build 133).

    Published: 29 Nov 2005
    5.4
    Medium

    CVE-2005-3887

    Last Modified: 16 Apr 2026

    Gadu-Gadu 7.20 does not properly handle MS-DOS device names in filenames, which allows remote attackers to (1) cause a denial of service (hang) via an image filename of AUX: sent twice (hang), or (2) write to the LPT1 port via a filename of "LPT1:".

    Published: 29 Nov 2005
    5
    Medium

    CVE-2005-3892

    Last Modified: 16 Apr 2026

    Gadu-Gadu 7.20 allows remote attackers to eavesdrop on a user via a web page that accesses the EasycallLite.oce ActiveX control, which can initiate an outgoing phone call and listen to the microphone.

    Published: 29 Nov 2005
    4.3
    Medium

    CVE-2005-3894

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) hex-encoded values in the QueueID parameter and (2) Action parameters.

    Published: 29 Nov 2005
    7.8
    High

    CVE-2005-3897

    Last Modified: 16 Apr 2026

    Apple Safari 2.0.2 allows remote attackers to cause a denial of service (system slowdown) via a Javascript BODY onload event that calls the window function.

    Published: 29 Nov 2005
    Unknown

    CVE-2006-0018

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-3899. Reason: This candidate is a duplicate of CVE-2005-3899. Notes: All CVE users should reference CVE-2005-3899 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 29 Nov 2005
    7.5
    High

    CVE-2005-2123

    Last Modified: 16 Apr 2026

    Multiple integer overflows in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allow remote attackers to execute arbitrary code via crafted Windows Metafile (WMF) and Enhanced Metafile (EMF) format images that lead to heap-based buffer overflows, as demonstrated using MRBP16::bCheckRecord.

    Published: 29 Nov 2005
    7.8
    High

    CVE-2005-3888

    Last Modified: 16 Apr 2026

    Memory leak in Gadu-Gadu 7.20 allows remote attackers to cause a denial of service via multiple DCC packets with a code other than 2 and a large size field, which allocates memory for the packet but does not free it after the packet has been dropped.

    Published: 29 Nov 2005
    7.8
    High

    CVE-2005-3891

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Gadu-Gadu 7.20 allows remote attackers to cause a denial of service (crash) via an image filename between exactly 192 to 200 characters, which does not account for the "imgcache\" string that is added to the end of the buffer.

    Published: 29 Nov 2005
    7.6
    High

    CVE-2005-2124

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1, related to "An unchecked buffer" and possibly buffer overflows, allows remote attackers to execute arbitrary code via a crafted Windows Metafile (WMF) format image, aka "Windows Metafile Vulnerability."

    Published: 29 Nov 2005
    7.8
    High

    CVE-2005-3889

    Last Modified: 16 Apr 2026

    Gadu-Gadu 7.20 allows remote attackers to cause a denial of service via multiple DCC packets with a code of 6 or 7, which triggers a large number of popup windows to the user and creates a large number of threads.

    Published: 29 Nov 2005
    7.8
    High

    CVE-2005-3890

    Last Modified: 16 Apr 2026

    Gadu-Gadu 7.20 allows remote attackers to cause a denial of service (crash and configuration loss) via a page with a large number of gg: URIs.

    Published: 29 Nov 2005
    7.5
    High

    CVE-2005-3893

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) user parameter in the Login action, and remote authenticated users via the (2) TicketID and (3) ArticleID parameters of the AgentTicketPlain action.

    Published: 29 Nov 2005
    7.8
    High

    CVE-2005-3896

    Last Modified: 16 Apr 2026

    Mozilla allows remote attackers to cause a denial of service (CPU consumption) via a Javascript BODY onload event that calls the window function.

    Published: 29 Nov 2005
    5.4
    Medium

    CVE-2005-3899

    Last Modified: 16 Apr 2026

    The automatic update feature in Google Talk allows remote attackers to cause a denial of service (CPU and memory consumption) by poisoning a target's DNS cache and causing a large update file to be sent, which consumes large amounts of CPU and memory during the signature verification, aka BenjiBug.

    Published: 29 Nov 2005
    Unknown

    CVE-2005-3898

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-3567. Reason: This candidate is a reservation duplicate of CVE-2005-3567. Notes: All CVE users should reference CVE-2005-3567 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 29 Nov 2005
    5.8
    Medium

    CVE-2005-3895

    Last Modified: 16 Apr 2026

    Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3, when AttachmentDownloadType is set to inline, renders text/html e-mail attachments as HTML in the browser when the queue moderator attempts to download the attachment, which allows remote attackers to execute arbitrary web script or HTML. NOTE: this particular issue is referred to as XSS by some sources.

    Published: 29 Nov 2005
    7.2
    High

    CVE-2005-3886

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Cisco Security Agent (CSA) 4.5.0 and 4.5.1 agents, when running on Windows systems, allows local users to bypass protections and gain system privileges by executing certain local software.

    Published: 29 Nov 2005
    2.1
    Low

    CVE-2005-3885

    Last Modified: 16 Apr 2026

    The ps2epsi extension shell script (ps2epsi.sh) in Inkscape before 0.41 allows local users to overwrite arbitrary files via a symlink attack on the tmpepsifile.epsi temporary file.

    Published: 29 Nov 2005
    7.5
    High

    CVE-2005-3880

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Omnistar KBase 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter in users/comments.php, (2) category_id and (3) id parameters in users/kb.php.

    Published: 29 Nov 2005
    7.5
    High

    CVE-2005-3861

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in content.php in phpGreetz 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.

    Published: 29 Nov 2005
    7.5
    High

    CVE-2005-3862

    Last Modified: 16 Apr 2026

    Buffer overflow in unalz before 0.53 allows remote attackers to execute arbitrary code via long file names in ALZ archives.

    Published: 29 Nov 2005
    7.5
    High

    CVE-2005-3863

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in kkstrtext.h in ktools library 0.3 and earlier, as used in products such as (1) centericq, (2) orpheus, (3) motor, and (4) groan, allows local users or remote attackers to execute arbitrary code via a long parameter to the VGETSTRING macro.

    Published: 29 Nov 2005
    7.5
    High

    CVE-2005-3868

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in K-Search 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) term, (2) id, (3) stat, and (4) source parameters to index.php, and (5) through the image parameters with an add request.

    Published: 29 Nov 2005
    4.3
    Medium

    CVE-2005-3869

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Google API Search 1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via hex-encoded values in the REQ parameter.

    Published: 29 Nov 2005
    7.5
    High

    CVE-2005-3870

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in edmobbs9r.php in edmoBBS 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) table and (2) messageID parameters.

    Published: 29 Nov 2005
    7.5
    High

    CVE-2005-3871

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Joels Bulletin board (JBB) 0.9.9rc3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) nr parameter in topiczeigen.php, (2) forum and (3) zeigeseite parameters in showforum.php, (4) forum parameter in newtopic.php, and (5) tidnr parameter in neuerbeitrag.php.

    Published: 29 Nov 2005
    7.5
    High

    CVE-2005-3877

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Simple Document Management System (SDMS) 2.0-CVS and earlier allow remote attackers to execute arbitrary SQL commands via the (1) folder_id parameter in list.php and (2) mid parameter in a view action to messages.php.

    Published: 29 Nov 2005
    6.4
    Medium

    CVE-2005-3878

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in PHP Doc System 1.5.1 and earlier allows remote attackers to access or include arbitrary files via a .. (dot dot) in the show parameter.

    Published: 29 Nov 2005
    7.5
    High

    CVE-2005-3874

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in netzbr.php in Netzbrett 1.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the p_entry parameter in an entry command to index.php.

    Published: 29 Nov 2005
    7.5
    High

    CVE-2005-3882

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in answer.php in FAQSystems FAQRing Knowledge Base Software 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 29 Nov 2005
    7.5
    High

    CVE-2005-3884

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in the search action in Zainu 2.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) term and (2) start parameters to index.php.

    Published: 29 Nov 2005
    7.5
    High

    CVE-2005-3881

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search.php in AtlantisFAQ Knowledge Base Software 2.03 and earlier allows remote attackers to execute arbitrary SQL commands via the searchStr parameter.

    Published: 29 Nov 2005
    7.5
    High

    CVE-2005-3879

    Last Modified: 24 Apr 2026

    Multiple SQL injection vulnerabilities in Softbiz Resource Repository Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) sbres_id parameter in (a) details_res.php, (b) refer_friend.php, and (c) report_link.php, and (2) the sbcat_id parameter in (d) showcats.php.

    Published: 29 Nov 2005
    7.5
    High

    CVE-2005-3865

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in AllWeb search 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the search parameter.

    Published: 29 Nov 2005
    7.5
    High

    CVE-2005-3873

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in topic.php in ShockBoard 3.0 and 4.0 allows remote attackers to execute arbitrary SQL commands via the offset parameter.

    Published: 29 Nov 2005
    7.5
    High

    CVE-2005-3859

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in q-news.php in Q-News 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.

    Published: 29 Nov 2005
    7.5
    High

    CVE-2005-3860

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in athena.php in Oliver May Athena PHP Website Administration 0.1a allows remote attackers to execute arbitrary PHP code via a URL in the athena_dir parameter.

    Published: 29 Nov 2005
    4.3
    Medium

    CVE-2005-3867

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in RevenuePilot Search Engine Script 1.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the REQ parameter, which is used when performing a search.

    Published: 29 Nov 2005
    7.5
    High

    CVE-2005-3876

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in adcbrowres.php in AD Center ADC2000 NG Pro 1.2 and NG Pro Lite allow remote attackers to execute arbitrary SQL commands via the (1) cat and (2) lang parameters.

    Published: 29 Nov 2005
    7.5
    High

    CVE-2005-3864

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in SourceWell 1.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the cnt parameter. NOTE: various reports indicate that the affected version is 1.1.3, but as of 2005-11-29, the most recent version appears to be 1.1.2.

    Published: 29 Nov 2005
    4.3
    Medium

    CVE-2005-3866

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in SearchFeed Search Engine 1.3.2 and earlier allows remote attackers to inject arbitrary HTML and web script, possibly via the REQ parameter, which is used when performing a search.

    Published: 29 Nov 2005
    7.5
    High

    CVE-2005-3872

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Ugroup 2.6.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) FORUM_ID parameter in forum.php, and the (2) TOPIC_ID, (3) FORUM_ID, and (4) CAT_ID parameters in topic.php.

    Published: 29 Nov 2005
    7.5
    High

    CVE-2005-3875

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Enterprise Connector 1.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the messageid parameter in (1) send.php or (2) a delete action in messages.php.

    Published: 29 Nov 2005
    4
    Medium

    CVE-2005-3856

    Last Modified: 16 Apr 2026

    The Popular URL capability (popularurls.cpp) in Krusader 1.60.0 and 1.70.0-beta1 saves passwords in cleartext in the krusaderrc file when the user enters URLs containing passwords in the panel URL field, which might allow attackers to access other sites.

    Published: 27 Nov 2005
    4.3
    Medium

    CVE-2005-3851

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.asp in Online Attendance System (OASYS) Lite 1.0 allows remote attackers to inject arbitrary web script or HTML via certain search parameters, possibly the keyword parameter.

    Published: 27 Nov 2005
    7.5
    High

    CVE-2005-3852

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search.asp in Online Work Order Suite (OWOS) Lite Edition for ASP 3.0 allows remote attackers to execute arbitrary SQL commands via the keyword parameter.

    Published: 27 Nov 2005
    7.5
    High

    CVE-2005-3853

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in snews.php in sNews 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category parameters to index.php.

    Published: 27 Nov 2005
    4.3
    Medium

    CVE-2005-3854

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in EasyPageCMS allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

    Published: 27 Nov 2005
    7.5
    High

    CVE-2005-3855

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in process.php in 1-2-3 music store allows remote attackers to execute arbitrary SQL commands via the AlbumID parameter.

    Published: 27 Nov 2005