CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2005-3640

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the IMAP Groupware Mail server of Floosietek FTGate (FTGate4) 4.1 allow remote attackers to execute arbitrary code via long arguments to various IMAP commands, as demonstrated with the EXAMINE command.

    Published: 16 Nov 2005
    7.5
    High

    CVE-2005-3642

    Last Modified: 16 Apr 2026

    IBM Informix Dynamic Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account by supplying an invalid username.

    Published: 16 Nov 2005
    5
    Medium

    CVE-2005-3633

    Last Modified: 16 Apr 2026

    HTTP response splitting vulnerability in frameset.htm in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to inject arbitrary HTML headers via the sap-exiturl parameter.

    Published: 16 Nov 2005
    7.5
    High

    CVE-2005-3639

    Last Modified: 16 Apr 2026

    PHP file inclusion vulnerability in the osTicket module in Help Center Live before 2.0.3 allows remote attackers to access or include arbitrary files via the file parameter, possibly due to a directory traversal vulnerability.

    Published: 16 Nov 2005
    7.5
    High

    CVE-2005-3641

    Last Modified: 16 Apr 2026

    Oracle Databases running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication by supplying a valid username.

    Published: 16 Nov 2005
    7.5
    High

    CVE-2005-3643

    Last Modified: 16 Apr 2026

    IBM DB2 Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account without supplying a password.

    Published: 16 Nov 2005
    Unknown

    CVE-2005-3637

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-3530. Reason: This candidate is a duplicate of CVE-2005-3530. Notes: All CVE users should reference CVE-2005-3530 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 16 Nov 2005
    4.3
    Medium

    CVE-2005-3635

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in SAP Web Application Server (WAS) 6.10 through 7.00 allow remote attackers to inject arbitrary web script or HTML via (1) the sap-syscmd in sap-syscmd and (2) the BspApplication field in the SYSTEM PUBLIC test application.

    Published: 16 Nov 2005
    4.3
    Medium

    CVE-2005-3638

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerabilities in Ekinboard 1.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in profile.php and (2) titles of posts.

    Published: 16 Nov 2005
    5
    Medium

    CVE-2005-3621

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in phpMyAdmin before 2.6.4-pl4 allows remote attackers to conduct HTTP response splitting attacks via unspecified scripts.

    Published: 16 Nov 2005
    5
    Medium

    CVE-2005-3622

    Last Modified: 16 Apr 2026

    phpMyAdmin 2.7.0-beta1 and earlier allows remote attackers to obtain the full path of the server via direct requests to multiple scripts in the libraries directory.

    Published: 16 Nov 2005
    10
    Critical

    CVE-2005-3344

    Last Modified: 16 Apr 2026

    The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access.

    Published: 16 Nov 2005
    6.8
    Medium

    CVE-2005-3543

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search.php in Phorum 5.0.0alpha through 5.0.20, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the forum_ids parameter.

    Published: 16 Nov 2005
    4.3
    Medium

    CVE-2005-3544

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in u2u.php in XMB 1.9.3 allows remote attackers to inject arbitrary web script or HTML via the username parameter.

    Published: 16 Nov 2005
    7.5
    High

    CVE-2005-3545

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php of the report module in ibProArcade 2.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.

    Published: 16 Nov 2005
    7.2
    High

    CVE-2005-3546

    Last Modified: 16 Apr 2026

    suid.cgi scripts in F-Secure (1) Internet Gatekeeper for Linux before 2.15.484 and (2) Anti-Virus Linux Gateway before 2.16 are installed SUID with world-executable permissions, which allows local users to gain privilege.

    Published: 16 Nov 2005
    4.3
    Medium

    CVE-2005-3547

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Invision Power Board 2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) adsess, (2) name, and (3) description parameters in admin.php, and the (4) ACP Notes, (5) Member Name, (6) Password, (7) Email Address, (8) Components, and multiple other input fields.

    Published: 16 Nov 2005
    Unknown

    CVE-2005-3542

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-3508. Reason: This candidate is a reservation duplicate of CVE-2005-3508. Notes: All CVE users should reference CVE-2005-3508 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 16 Nov 2005
    4.3
    Medium

    CVE-2005-3552

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple vectors in (1) login/profile.php, (2) login/userinfo.php, (3) admin/admin.php, (4) imcenter.php, and the (5) referer statistics, the (6) HTML title element and (7) logo alt attributes in forum postings, and the (8) Homepage field in the Guestbook.

    Published: 16 Nov 2005
    7.5
    High

    CVE-2005-3553

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in include.php in PHPKIT 1.6.1 R2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in conjunction with the login/userinfo.php path and (2) the session parameter (aka the PHPKITSID variable).

    Published: 16 Nov 2005
    7.5
    High

    CVE-2005-3558

    Last Modified: 16 Apr 2026

    PHP file inclusion vulnerability in index.php in OSTE 1.0 allows remote attackers to execute arbitrary code via the (1) page and (2) site parameters.

    Published: 16 Nov 2005
    5
    Medium

    CVE-2005-3559

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in vmail.cgi in Asterisk 1.0.9 through 1.2.0-beta1 allows remote attackers to access WAV files via a .. (dot dot) in the folder parameter.

    Published: 16 Nov 2005
    Unknown

    CVE-2005-3561

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-2954. Reason: This candidate is a reservation duplicate of CVE-2005-2954. Notes: All CVE users should reference CVE-2005-2954 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 16 Nov 2005
    7.2
    High

    CVE-2005-3564

    Last Modified: 16 Apr 2026

    envd daemon in HP-UX B.11.00 through B.11.11 allows local users to obtain privileges via unknown attack vectors.

    Published: 16 Nov 2005
    5.8
    Medium

    CVE-2005-3567

    Last Modified: 16 Apr 2026

    slapd daemon in IBM Tivoli Directory Server (ITDS) 5.2.0 and 6.0.0 binds using SASL EXTERNAL, which allows attackers to bypass authentication and modify and delete directory data via unknown attack vectors.

    Published: 16 Nov 2005
    5
    Medium

    CVE-2005-3569

    Last Modified: 16 Apr 2026

    INSO service in IBM DB2 Content Manager before 8.2 Fix Pack 10 on AIX allows attackers to cause a denial of service (application crash) via unknown attack vectors involving LZH files.

    Published: 16 Nov 2005
    Unknown

    CVE-2005-3563

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-2956. Reason: This candidate is a duplicate of CVE-2005-2956. Notes: All CVE users should reference CVE-2005-2956 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 16 Nov 2005
    5
    Medium

    CVE-2005-3574

    Last Modified: 16 Apr 2026

    PHP file inclusion vulnerability in index.php of iCMS allows remote attackers to include arbitrary files via the page parameter.

    Published: 16 Nov 2005
    7.5
    High

    CVE-2005-3575

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in show.php in Cyphor 0.19 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 16 Nov 2005
    5
    Medium

    CVE-2005-3576

    Last Modified: 16 Apr 2026

    ts.exe in Walla TeleSite 3.0 and earlier allows remote attackers to access privileged information by entering the article number in tsurl parameter.

    Published: 16 Nov 2005
    4.3
    Medium

    CVE-2005-3577

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability (XSS) in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the sug parameter.

    Published: 16 Nov 2005
    7.2
    High

    CVE-2005-3580

    Last Modified: 16 Apr 2026

    QDBM before 1.8.33-r2 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.

    Published: 16 Nov 2005
    7.2
    High

    CVE-2005-3581

    Last Modified: 16 Apr 2026

    GDAL before 1.3.0-r1 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.

    Published: 16 Nov 2005
    7.8
    High

    CVE-2005-3583

    Last Modified: 16 Apr 2026

    (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.2_08, 1.4.2_09, and 1.5.0_05 and possibly other versions allow remote attackers to cause a denial of service (JVM unresponsive) via a crafted serialized object, such as a font object as demonstrated on JBoss.

    Published: 16 Nov 2005
    4.3
    Medium

    CVE-2005-3584

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in forum.php in PhpWebThings 1.4.4 allows remote attackers to inject arbitrary web script or HTML via the forum parameter.

    Published: 16 Nov 2005
    7.5
    High

    CVE-2005-3585

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in forum.php in PhpWebThings 1.4.4 allows remote attackers to execute arbitrary SQL commands via the forum parameter.

    Published: 16 Nov 2005
    5
    Medium

    CVE-2005-3586

    Last Modified: 16 Apr 2026

    content.php in Mambo 4.5.2 through 4.5.2.3 allows remote attackers to obtain the installation path of the application via a URL that causes the application to return an error.

    Published: 16 Nov 2005
    7.8
    High

    CVE-2005-3589

    Last Modified: 16 Apr 2026

    Buffer overflow in FileZilla Server Terminal 0.9.4d may allow remote attackers to cause a denial of service (terminal crash) via a long USER ftp command.

    Published: 16 Nov 2005
    7.5
    High

    CVE-2005-3591

    Last Modified: 16 Apr 2026

    Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via parameters to the ActionDefineFunction ActionScript call in a SWF file, which causes an improper memory access condition, a different vulnerability than CVE-2005-2628.

    Published: 16 Nov 2005
    5
    Medium

    CVE-2005-3592

    Last Modified: 16 Apr 2026

    index.php CuteNews 1.4.0 and earlier allows remote attackers to obtain the path of the installation path of the application by triggering an error message, such as by entering multiple ../ (dot dot slash) in the archive parameter.

    Published: 16 Nov 2005
    5
    Medium

    CVE-2005-3594

    Last Modified: 16 Apr 2026

    game_score.php in e107 allows remote attackers to insert high scores via HTTP POST methods utilizing the $player_name, $player_score, and $game_name variables.

    Published: 16 Nov 2005
    6.5
    Medium

    CVE-2005-3549

    Last Modified: 16 Apr 2026

    Direct code injection vulnerability in Task Manager in Invision Power Board 2.0.1 allows limited remote attackers to execute arbitrary code by referencing the file in "Task PHP File To Run" field and selecting "Run Task Now".

    Published: 16 Nov 2005
    5
    Medium

    CVE-2005-3551

    Last Modified: 16 Apr 2026

    toendaCMS before 0.6.2 stores user account and session data in the web root directory, which allows remote attackers to obtain sensitive information via a direct request to the appropriate XML file.

    Published: 16 Nov 2005
    6.5
    Medium

    CVE-2005-3555

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in PHPlist 2.10.1 and earlier allow authenticated remote attackers with administrator privileges to execute arbitrary SQL commands via the id parameter in the (1) editattributes or (2) admin page.

    Published: 16 Nov 2005
    4.3
    Medium

    CVE-2005-3566

    Last Modified: 16 Apr 2026

    Buffer overflow in various ha commands of VERITAS Cluster Server for UNIX before 4.0MP2 allows local users to execute arbitrary code via a long VCSI18N_LANG environment variable to (1) haagent, (2) haalert, (3) haattr, (4) hacli, (5) hacli_runcmd, (6) haclus, (7) haconf, (8) hadebug, (9) hagrp, (10) hahb, (11) halog, (12) hareg, (13) hares, (14) hastatus, (15) hasys, (16) hatype, (17) hauser, and (18) tststew.

    Published: 16 Nov 2005
    5
    Medium

    CVE-2005-3571

    Last Modified: 16 Apr 2026

    PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique 1.0, (c) PHPCurrently 2.0, (d) PHPFanBase 2.1, and (e) PHPQuotes 1.0 allows remote attackers to include arbitrary local files via the siteurl parameter when register_globals is enabled. NOTE: It was later reported that PHPFanBase 2.2 is also affected.

    Published: 16 Nov 2005
    7.5
    High

    CVE-2005-3596

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in ASPKnowledgebase allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password fields in adminlogin.asp.

    Published: 16 Nov 2005
    10
    Critical

    CVE-2005-2659

    Last Modified: 16 Apr 2026

    Buffer overflow in the LZX decompression in CHM Lib (chmlib) 0.35, as used in products such as KchmViewer, has unknown impact and attack vectors.

    Published: 16 Nov 2005
    4
    Medium

    CVE-2005-3548

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Task Manager in Invision Power Board (IP.Board) 2.0.1 allows limited remote attackers to include files via a .. (dot dot) in the "Task PHP File To Run" field.

    Published: 16 Nov 2005
    5
    Medium

    CVE-2005-3550

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in admin.php in toendaCMS before 0.6.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the id_user parameter.

    Published: 16 Nov 2005