CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2005-3691

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the IMAP service (meimaps.exe) of MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier allows remote attackers to create or rename arbitrary mail directories via the mailbox name argument of the (1) create or (2) rename commands.

    Published: 19 Nov 2005
    5
    Medium

    CVE-2005-3687

    Last Modified: 16 Apr 2026

    cancel_account.php in WHM AutoPilot 2.5.30 and earlier allows remote attackers to cancel requests for arbitrary accounts via a modified c parameter.

    Published: 19 Nov 2005
    7.5
    High

    CVE-2005-3686

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search.inc.php in Unclassified NewsBoard before 1.5.3 Patch 4 allows remote attackers to execute arbitrary SQL commands via the (1) DateFrom or (2) DateUntil parameter to forum.php.

    Published: 19 Nov 2005
    4.3
    Medium

    CVE-2005-3688

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in members.php in XMB 1.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the "Your Current Mood" field in the registration page.

    Published: 19 Nov 2005
    5
    Medium

    CVE-2005-3689

    Last Modified: 16 Apr 2026

    post.php in XMB 1.9.2 allows remote attackers to obtain the installation path via an invalid fid parameter in a newthread action.

    Published: 19 Nov 2005
    4.3
    Medium

    CVE-2005-3692

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) retid parameter in badlogin.php, (2) Content-Type headers in HTML mails, and (3) HTML mail attachments.

    Published: 19 Nov 2005
    7.5
    High

    CVE-2005-3684

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in freeFTPd 1.0.8, without logging enabled, allow remote authenticated attackers to cause a denial of service (application crash), and possibly execute arbitrary code, via long (1) MKD and (2) DELE commands.

    Published: 19 Nov 2005
    7.5
    High

    CVE-2005-3683

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in freeFTPd before 1.0.9 with Logging enabled, allows remote attackers to cause a denial of service (application crash), and possibly execute arbitrary code, via a long USER command.

    Published: 19 Nov 2005
    7.5
    High

    CVE-2005-3677

    Last Modified: 16 Apr 2026

    Buffer overflow in RealNetworks RealPlayer 10 and 10.5 allows remote attackers to execute arbitrary code via a crafted image in a RealPlayer Skin (RJS) file. NOTE: due to the lack of details, it is unclear how this is different than CVE-2005-2629 and CVE-2005-2630, but the vendor advisory implies that it is different.

    Published: 18 Nov 2005
    7.5
    High

    CVE-2005-3676

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in download.php in PhpWebThings 1.4.4 allows remote attackers to execute arbitrary SQL commands via the file parameter.

    Published: 18 Nov 2005
    7.8
    High

    CVE-2005-3675

    Last Modified: 16 Apr 2026

    The Transmission Control Protocol (TCP) allows remote attackers to cause a denial of service (bandwidth consumption) by sending ACK messages for packets that have not yet been received (optimistic ACKs), which can cause the sender to increase its transmission rate until it fills available bandwidth.

    Published: 18 Nov 2005
    5
    Medium

    CVE-2005-3678

    Last Modified: 16 Apr 2026

    Google Talk before 1.0.0.76, with email notification enabled, allows remote attackers to cause a denial of service (connection reset) via email with a blank sender.

    Published: 18 Nov 2005
    5.1
    Medium

    CVE-2005-2630

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in DUNZIP32.DLL for RealPlayer 8, 10, and 10.5 and RealOne Player 1 and 2 allows remote attackers to execute arbitrary code via a crafted RealPlayer Skin (RJS) file, a different vulnerability than CVE-2004-1094.

    Published: 18 Nov 2005
    7.5
    High

    CVE-2005-3679

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in admin/index.php in ActiveCampaign 1-2-All Broadcast Email allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username field in the admin control panel.

    Published: 18 Nov 2005
    6.4
    Medium

    CVE-2005-3680

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in editor_registry.php in XOOPS 2.2.3 allows remote attackers to read or include arbitrary local files via a .. (dot dot) in the xoopsConfig[language] parameter.

    Published: 18 Nov 2005
    7.5
    High

    CVE-2005-3681

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in viewcat.php in XOOPS WF-Downloads module 2.05 allows remote attackers to execute arbitrary SQL commands via the list parameter.

    Published: 18 Nov 2005
    7.5
    High

    CVE-2005-3682

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Wizz Forum 1.20 allow remote attackers to execute arbitrary SQL commands via (1) the AuthID parameter in ForumAuthDetails.php, and the TopicID parameter in (2) ForumTopicDetails.php and (3) ForumReply.php.

    Published: 18 Nov 2005
    1.9
    Low

    CVE-2005-3349

    Last Modified: 16 Apr 2026

    GNU Gnump3d before 2.9.8 allows local users to modify or delete arbitrary files via a symlink attack on the index.lok temporary file.

    Published: 18 Nov 2005
    7.5
    High

    CVE-2005-3314

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the IMAP daemon in Novell Netmail 3.5.2 allows remote attackers to execute arbitrary code via "long verb arguments."

    Published: 18 Nov 2005
    6.4
    Medium

    CVE-2005-3355

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in GNU Gnump3d before 2.9.8 has unknown impact via "CGI parameters, and cookie values".

    Published: 18 Nov 2005
    7.8
    High

    CVE-2005-3673

    Last Modified: 16 Apr 2026

    The Internet Key Exchange version 1 (IKEv1) implementation in Check Point products allows remote attackers to cause a denial of service via certain crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.

    Published: 18 Nov 2005
    5
    Medium

    CVE-2005-3668

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in multiple unspecified implementations of Internet Key Exchange version 1 (IKEv1) have multiple unspecified attack vectors and impacts related to denial of service, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of information in the original sources, it is likely that this candidate will be REJECTed once it is known which implementations are actually vulnerable.

    Published: 18 Nov 2005
    7.8
    High

    CVE-2005-3674

    Last Modified: 16 Apr 2026

    The Internet Key Exchange version 1 (IKEv1) implementation in the libike library in Sun Solaris 9 and 10 allows remote attackers to cause a denial of service (in.iked crash) via certain crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.

    Published: 18 Nov 2005
    7.8
    High

    CVE-2005-3671

    Last Modified: 16 Apr 2026

    The Internet Key Exchange version 1 (IKEv1) implementation in Openswan 2 (openswan-2) before 2.4.4, and freeswan in SUSE LINUX 9.1 before 2.04_1.5.4-1.23, allow remote attackers to cause a denial of service via (1) a crafted packet using 3DES with an invalid key length, or (2) unspecified inputs when Aggressive Mode is enabled and the PSK is known, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.

    Published: 18 Nov 2005
    10
    Critical

    CVE-2005-3666

    Last Modified: 16 Apr 2026

    Multiple unspecified format string vulnerabilities in multiple unspecified implementations of Internet Key Exchange version 1 (IKEv1) have multiple unspecified attack vectors and impacts, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of information in the original sources, it is likely that this candidate will be REJECTed once it is known which implementations are actually vulnerable.

    Published: 18 Nov 2005
    5
    Medium

    CVE-2005-3667

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in multiple unspecified implementations of Internet Key Exchange version 1 (IKEv1) have multiple unspecified attack vectors and impacts related to denial of service, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of information in the original sources, it is likely that this candidate will be REJECTed once it is known which implementations are actually vulnerable. In addition, since "denial of service" is an impact and not a vulnerability, it is unknown which underlying vulnerabilities are actually covered by this particular candidate.

    Published: 18 Nov 2005
    5
    Medium

    CVE-2005-3669

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a denial of service (device reset) via certain malformed IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the Cisco advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.

    Published: 18 Nov 2005
    7.8
    High

    CVE-2005-3670

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in HP HP-UX B.11.00, B.11.11, and B.11.23 running IPSec, HP Jetdirect 635n IPv6/IPsec Print Server, and HP Tru64 UNIX 5.1B-3 and 5.1B-2/PK4, allow remote attackers to cause a denial of service via certain IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the HP advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.

    Published: 18 Nov 2005
    5
    Medium

    CVE-2005-3672

    Last Modified: 16 Apr 2026

    The Internet Key Exchange version 1 (IKEv1) implementation in Stonesoft StoneGate Firewall before 2.6.1 allows remote attackers to cause a denial of service via certain crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the Stonesoft advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.

    Published: 18 Nov 2005
    7.2
    High

    CVE-2005-3663

    Last Modified: 16 Apr 2026

    Unquoted Windows search path vulnerability in Kaspersky Anti-Virus 5.0 might allow local users to gain privileges via a malicious "program.exe" file in the C: folder.

    Published: 18 Nov 2005
    7.5
    High

    CVE-2005-3664

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Kaspersky Anti-Virus Engine, as used in Kaspersky Personal 5.0.227, Anti-Virus On-Demand Scanner for Linux 5.0.5, and F-Secure Anti-Virus for Linux 4.50 allows remote attackers to execute arbitrary code via a crafted CHM file.

    Published: 18 Nov 2005
    7.5
    High

    CVE-2005-1925

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in Tikiwiki before 1.9.1 allow remote attackers to read arbitrary files and execute commands via (1) the suck_url parameter to tiki-editpage.php or (2) language parameter to tiki-user_preferences.php.

    Published: 18 Nov 2005
    7.2
    High

    CVE-2005-2939

    Last Modified: 16 Apr 2026

    Unquoted Windows search path vulnerability in VMWare Workstation 5.0.0 build-13124 might allow local users to gain privileges via a malicious "program.exe" file in the C: folder.

    Published: 18 Nov 2005
    7.2
    High

    CVE-2005-2936

    Last Modified: 16 Apr 2026

    Unquoted Windows search path vulnerability in RealNetworks RealPlayer 10.5 6.0.12.1040 through 6.0.12.1348, RealPlayer 10, RealOne Player v2, RealOne Player v1, and RealPlayer 8 before 20060322 might allow local users to gain privileges via a malicious C:\program.exe file.

    Published: 18 Nov 2005
    10
    Critical

    CVE-2005-3116

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in a shared library as used by the Volume Manager daemon (vmd) in VERITAS NetBackup Enterprise Server 5.0 MP1 to MP5 and 5.1 up to MP3A allows remote attackers to execute arbitrary code via a crafted packet.

    Published: 18 Nov 2005
    7.2
    High

    CVE-2005-2938

    Last Modified: 16 Apr 2026

    Unquoted Windows search path vulnerability in iTunesHelper.exe in iTunes 4.7.1.30 and iTunes 5 for Windows might allow local users to gain privileges via a malicious C:\program.exe file.

    Published: 18 Nov 2005
    7.2
    High

    CVE-2005-2940

    Last Modified: 16 Apr 2026

    Unquoted Windows search path vulnerability in Microsoft Antispyware 1.0.509 (Beta 1) might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, involving the programs (1) GIANTAntiSpywareMain.exe, (2) gcASNotice.exe, (3) gcasServ.exe, (4) gcasSWUpdater.exe, or (5) GIANTAntiSpywareUpdater.exe. NOTE: it is not clear whether this overlaps CVE-2005-2935.

    Published: 18 Nov 2005
    5
    Medium

    CVE-2005-3189

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Qualcomm WorldMail IMAP Server allows remote attackers to read arbitrary email messages via ".." sequences in the SELECT command.

    Published: 18 Nov 2005
    4.3
    Medium

    CVE-2005-3348

    Last Modified: 16 Apr 2026

    HTTP response splitting vulnerability in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egroupware before 1.0.0.009, allows remote attackers to spoof web content and poison web caches via CRLF sequences in the charset parameter.

    Published: 18 Nov 2005
    6.8
    Medium

    CVE-2005-3347

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egrouwpware before 1.0.0.009, allow remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) sensor_program parameter or the (2) _SERVER[HTTP_ACCEPT_LANGUAGE] parameter, which overwrites an internal variable, a variant of CVE-2003-0536. NOTE: due to a typo in an advisory, an issue in osh was inadvertently linked to this identifier; the proper identifier for the osh issue is CVE-2005-3346.

    Published: 18 Nov 2005
    5
    Medium

    CVE-2006-2758

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %2e%2e%5c (encoded ../) in the URL. NOTE: this might be the same issue as CVE-2005-3747.

    Published: 18 Nov 2005
    2.6
    Low

    CVE-2005-3649

    Last Modified: 16 Apr 2026

    jumpto.php in Moodle 1.5.2 allows remote attackers to redirect users to other sites via the jump parameter.

    Published: 17 Nov 2005
    7.5
    High

    CVE-2005-3646

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in lib-sessions.inc.php in phpAdsNew and phpPgAds 2.0.6 and possibly earlier versions allow remote attackers to execute arbitrary SQL commands via the sessionID parameter in (1) logout.php and (2) index.php.

    Published: 17 Nov 2005
    5
    Medium

    CVE-2005-3645

    Last Modified: 16 Apr 2026

    phpAdsNew and phpPgAds 2.0.6 and possibly earlier versions allows remote attackers to obtain the application installation path and other sensitive information via direct requests to (1) create.php, and if display_errors is enabled, (2) lib-updates.inc.php, (3) lib-targetstats.inc.php, (4) lib-size.inc.php, (5) lib-misc-stats.inc.php, (6) lib-hourly-hosts.inc.php, (7) lib-hourly.inc.php, (8) lib-history.inc.php, and (9) graph-daily.php.

    Published: 17 Nov 2005
    4.6
    Medium

    CVE-2005-3647

    Last Modified: 16 Apr 2026

    Folder Guard allows local users to bypass protections by running from or installing to the temporary files directory.

    Published: 17 Nov 2005
    7.5
    High

    CVE-2005-3648

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in the get_record function in datalib.php in Moodle 1.5.2 allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) category.php and (2) info.php.

    Published: 17 Nov 2005
    9.3
    Critical

    CVE-2005-3650

    Last Modified: 16 Apr 2026

    The CodeSupport.ocx ActiveX control, as used by Sony to uninstall the First4Internet XCP DRM, has "safe for scripting" enabled, which allows remote attackers to execute arbitrary code by calling vulnerable functions such as RebootMachine, IsAdministrator, and ExecuteCode.

    Published: 17 Nov 2005
    7.8
    High

    CVE-2005-3644

    Last Modified: 16 Apr 2026

    PNP_GetDeviceList (upnp_getdevicelist) in UPnP for Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a DCE RPC request that specifies a large output buffer size, a variant of CVE-2006-6296, and a different vulnerability than CVE-2005-2120.

    Published: 17 Nov 2005
    5
    Medium

    CVE-2005-3634

    Last Modified: 16 Apr 2026

    frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.

    Published: 16 Nov 2005
    4.3
    Medium

    CVE-2005-3636

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in SAP Web Application Server (WAS) 6.10 allows remote attackers to inject arbitrary web script or HTML via Error Pages.

    Published: 16 Nov 2005