CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2005-3850

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.asp in Online Knowledge Base System (OKBSYS) Lite Edition 1.0 allows remote attackers to inject arbitrary web script or HTML via hex-encoded values in the q parameter.

    Published: 27 Nov 2005
    4.3
    Medium

    CVE-2005-3849

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Search module in PmWiki up to 2.0.12 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Published: 27 Nov 2005
    5.5
    Medium

    CVE-2005-3847

    Last Modified: 16 Apr 2026

    The handle_stop_signal function in signal.c in Linux kernel 2.6.11 up to other versions before 2.6.13 and 2.6.12.6 allows local users to cause a denial of service (deadlock) by sending a SIGKILL to a real-time threaded process while it is performing a core dump.

    Published: 27 Nov 2005
    7.5
    High

    CVE-2005-3838

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in search.php in IsolSoft Support Center 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) lorder, (2) Priority, (3) Status, (4) Category, (5) searchvalue, and (6) field parameter.

    Published: 26 Nov 2005
    4.3
    Medium

    CVE-2005-3839

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in SupportPRO Supportdesk allows remote attackers to inject arbitrary web script or HTML via the (1) post tickers and (2) view tickets options.

    Published: 26 Nov 2005
    4.3
    Medium

    CVE-2005-3841

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in kPlaylist 1.6 (build 400), and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the searchfor search parameter.

    Published: 26 Nov 2005
    7.5
    High

    CVE-2005-3842

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in pdjk-support suite 1.1a and earlier allows remote attackers to execute arbitrary SQL commands via the (1) rowstart, (2) news_id, and (3) faq_id parameters.

    Published: 26 Nov 2005
    7.5
    High

    CVE-2005-3846

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in news.php in Fantastic News 2.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Published: 26 Nov 2005
    7.5
    High

    CVE-2005-3844

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in phpWordPress PHP News and Article Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the (1) poll and (2) category parameters to index.php, and (3) the ctg parameter in an archive action.

    Published: 26 Nov 2005
    7.5
    High

    CVE-2005-3845

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in invoices.php in EZ Invoice Inc 2.0 allows remote attackers to execute arbitrary SQL commands via the i parameter. NOTE: the vendor has stated "EZ Invoice, Inc has a patah available. Please email [email protected] and EZI will email you the patch to fix this small issue."

    Published: 26 Nov 2005
    7.5
    High

    CVE-2005-3840

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in kb.php in Omnistar Live 5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category_id parameter. NOTE: due to a typo, an Internet Explorer issue was incorrectly assigned this identifier, but the correct identifier is CVE-2005-3240.

    Published: 26 Nov 2005
    7.5
    High

    CVE-2005-3843

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in faq.php in Nicecoder iDesk 1.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Published: 26 Nov 2005
    7.5
    High

    CVE-2005-3833

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in songinfo.php in Tunez 1.21 and earlier allows remote attackers to execute arbitrary SQL commands via the song_id parameter.

    Published: 26 Nov 2005
    4.3
    Medium

    CVE-2005-3837

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the search module in sCssBoard 1.2 and 1.12, and earlier versions, allows remote attackers to inject arbitrary web script or HTML via the search_term parameter.

    Published: 26 Nov 2005
    7.5
    High

    CVE-2005-3835

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in support/index.php in DeskLance 2.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the main parameter.

    Published: 26 Nov 2005
    7.5
    High

    CVE-2005-3836

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in DeskLance 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the announce parameter.

    Published: 26 Nov 2005
    4.3
    Medium

    CVE-2005-3834

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in Tunez 1.21 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchFor parameter.

    Published: 26 Nov 2005
    5
    Medium

    CVE-2005-3830

    Last Modified: 16 Apr 2026

    index.php in ActiveCampaign SupportTrio 1.4 and earlier allows remote attackers to read or include arbitrary files via the page parameter, possibly due to a directory traversal vulnerability.

    Published: 26 Nov 2005
    5.1
    Medium

    CVE-2005-3831

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in (1) CxZIP60.dll and (2) CxZIP60u.dll, as used in SpeedProject products including (a) ZipStar 5.0 Build 4285, (b) Squeez 5.0 Build 4285, and (c) SpeedCommander 11.0 Build 4430 and 10.51 Build 4430, allows user-assisted attackers to execute arbitrary code via a ZIP archive containing a long filename.

    Published: 26 Nov 2005
    5.1
    Medium

    CVE-2005-3832

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in (1) CxUux60.dll and (2) CxUux60u.dll, as used in SpeedProject products including (a) Squeez 5.0 Build 4285, and (b) SpeedCommander 11.0 Build 4430 and 10.51 Build 4430, allows user-assisted attackers to execute arbitrary code via a ZIP archive containing a long filename.

    Published: 26 Nov 2005
    7.5
    High

    CVE-2005-3827

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in product_cat in AgileBill 1.4.92 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 26 Nov 2005
    7.8
    High

    CVE-2005-3829

    Last Modified: 16 Apr 2026

    index.php in ActiveCampaign KnowledgeBuilder 2.4 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an invalid category parameter, which causes a large number of SQL queries to be processed.

    Published: 26 Nov 2005
    7.5
    High

    CVE-2005-3828

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in ActiveCampaign KnowledgeBuilder 2.4 and earlier allows remote attackers to execute arbitrary SQL commands via the article parameter.

    Published: 26 Nov 2005
    4.3
    Medium

    CVE-2005-3814

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in SmartPPC Pro allow remote attackers to inject arbitrary web script or HTML via the username parameter in (1) directory.php, (2) frames.php, and (3) search.php.

    Published: 26 Nov 2005
    7.5
    High

    CVE-2005-3815

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in forum.php in Orca Forum 4.3b and earlier allows remote attackers to execute arbitrary SQL commands via the msg parameter.

    Published: 26 Nov 2005
    7.5
    High

    CVE-2005-3816

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in forum.php in freeForum 1.1 and earlier and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter or (2) thread parameter in thread mode.

    Published: 26 Nov 2005
    4.3
    Medium

    CVE-2005-3821

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in vTiger CRM 4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via multiple vectors, including the account name.

    Published: 26 Nov 2005
    7.5
    High

    CVE-2005-3822

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username in the login form or (2) record parameter, as demonstrated in the EditView action for the Contacts module.

    Published: 26 Nov 2005
    7.5
    High

    CVE-2005-3823

    Last Modified: 16 Apr 2026

    The Users module in vTiger CRM 4.2 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary file in the templatename parameter, which is passed to the eval function.

    Published: 26 Nov 2005
    5
    Medium

    CVE-2005-3824

    Last Modified: 16 Apr 2026

    The uploads module in vTiger CRM 4.2 and earlier allows remote attackers to upload arbitrary files, such as PHP files, via the add2db action.

    Published: 26 Nov 2005
    7.5
    High

    CVE-2005-3825

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in Comdev Vote Caster 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the campaign_id parameter in a result action.

    Published: 26 Nov 2005
    4.3
    Medium

    CVE-2005-3818

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) various input fields, including the contact, lead, and first or last name fields, (2) the record parameter in a DetailView action in the Leads module for index.php, (3) the $_SERVER['PHP_SELF'] variable, which is used in multiple locations such as index.php, and (4) aggregated RSS feeds in the RSS aggregation module.

    Published: 26 Nov 2005
    6.8
    Medium

    CVE-2005-3812

    Last Modified: 16 Apr 2026

    freeFTPd 1.0.10 allows remote authenticated users to cause a denial of service (null dereference and crash) via a PORT command with missing arguments.

    Published: 26 Nov 2005
    7.5
    High

    CVE-2005-3819

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary SQL commands and bypass authentication via the (1) user_name and (2) date parameter in the HelpDesk module.

    Published: 26 Nov 2005
    6.4
    Medium

    CVE-2005-3820

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in index.php in vTiger CRM 4.2 and earlier allow remote attackers to read or include arbitrary files, an ultimately execute arbitrary PHP code, via .. (dot dot) and null byte ("%00") sequences in the (1) module parameter and (2) action parameter in the Leads module, as also demonstrated by injecting PHP code into log messages and accessing the log file.

    Published: 26 Nov 2005
    7.5
    High

    CVE-2005-3817

    Last Modified: 6 Apr 2026

    Multiple SQL injection vulnerabilities in Softbiz Web Host Directory Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter in search_result.php, (2) sbres_id parameter in review.php, (3) cid parameter in browsecats.php, (4) h_id parameter in email.php, and (5) an unspecified parameter to the search module.

    Published: 26 Nov 2005
    4
    Medium

    CVE-2005-3813

    Last Modified: 16 Apr 2026

    IMAP service (meimaps.exe) of MailEnable Professional 1.7 and Enterprise 1.1 allows remote authenticated attackers to cause a denial of service (application crash) by using RENAME with a non-existent mailbox, a different vulnerability than CVE-2005-3690.

    Published: 26 Nov 2005
    7.5
    High

    CVE-2005-3826

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Ezyhelpdesk 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) edit_id, (2) faq_id, and (3) c_id parameters in a query string, and (4) the search engine, possibly involving the search_string parameter.

    Published: 26 Nov 2005
    5
    Medium

    CVE-2005-3811

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in admin/main.php in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows remote attackers to overwrite arbitrary files with session information via the sid parameter.

    Published: 25 Nov 2005
    4.9
    Medium

    CVE-2005-3808

    Last Modified: 16 Apr 2026

    Integer overflow in the invalidate_inode_pages2_range function in mm/truncate.c in Linux kernel 2.6.11 to 2.6.14 allows local users to cause a denial of service (hang) via 64-bit mmap calls that are not properly handled on a 32-bit system.

    Published: 25 Nov 2005
    4.9
    Medium

    CVE-2005-3805

    Last Modified: 16 Apr 2026

    A locking problem in POSIX timer cleanup handling on exit in Linux kernel 2.6.10 to 2.6.14, when running on SMP systems, allows local users to cause a denial of service (deadlock) involving process CPU timers.

    Published: 25 Nov 2005
    4.9
    Medium

    CVE-2005-3807

    Last Modified: 16 Apr 2026

    Memory leak in the VFS file lease handling in locks.c in Linux kernels 2.6.10 to 2.6.15 allows local users to cause a denial of service (memory exhaustion) via certain Samba activities that cause an fasync entry to be re-allocated by the fcntl_setlease function after the fasync queue has already been cleaned by the locks_delete_lock function.

    Published: 25 Nov 2005
    7.8
    High

    CVE-2005-3809

    Last Modified: 16 Apr 2026

    The nfattr_to_tcp function in ip_conntrack_proto_tcp.c in ctnetlink in Linux kernel 2.6.14 up to 2.6.14.3 allows attackers to cause a denial of service (kernel oops) via an update message without private protocol information, which triggers a null dereference.

    Published: 25 Nov 2005
    7.8
    High

    CVE-2005-3810

    Last Modified: 16 Apr 2026

    ip_conntrack_proto_icmp.c in ctnetlink in Linux kernel 2.6.14 up to 2.6.14.3 allows attackers to cause a denial of service (kernel oops) via a message without ICMP ID (ICMP_ID) information, which leads to a null dereference.

    Published: 25 Nov 2005
    4.3
    Medium

    CVE-2005-3790

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in act_newsletter.php in phpwcms 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) i and (2) text parameters.

    Published: 24 Nov 2005
    7.5
    High

    CVE-2005-3792

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in the Search module in PHP-Nuke 7.8, and possibly other versions before 7.9 with patch 3.1, allows remote attackers to execute arbitrary SQL commands, as demonstrated via the query parameter in a stories type.

    Published: 24 Nov 2005
    7.5
    High

    CVE-2005-3793

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in AlstraSoft Affiliate Network Pro 7.2 allow remote attackers to bypass authentication and execute arbitrary SQL commands via the (1) username or (2) password to admin/admin_validate_login, or the (3) login, (4) password, and (5) flag parameters to login_validate.php.

    Published: 24 Nov 2005
    5
    Medium

    CVE-2005-3794

    Last Modified: 16 Apr 2026

    AlstraSoft Affiliate Network Pro 7.2 allows remote attackers to obtain sensitive information via a direct request to scripts such as (1) togateway.php and (2) other unspecified scripts.

    Published: 24 Nov 2005
    7.5
    High

    CVE-2005-3798

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in admin/index.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary SQL commands via the username field.

    Published: 24 Nov 2005
    5
    Medium

    CVE-2005-3799

    Last Modified: 16 Apr 2026

    phpBB 2.0.18 allows remote attackers to obtain sensitive information via a large SQL query, which generates an error message that reveals SQL syntax or the full installation path.

    Published: 24 Nov 2005