CVE Feed

    Dashboard / CVE

    5.1
    Medium

    CVE-2005-3554

    Last Modified: 16 Apr 2026

    Multiple eval injection vulnerabilities in the help function in PHPKIT 1.6.1 R2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary code on the server via unknown attack vectors involving uninitialized variables.

    Published: 16 Nov 2005
    4.3
    Medium

    CVE-2005-3556

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PHPlist 2.10.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listname parameter in (a) admin/editlist.php, (2) title parameter in (b) admin/spageedit.php, (3) title field in (c) admin/template.php, (4) filter, (5) delete, and (6) start parameters in (d) admin/eventlog.php, (7) id parameter in (e) admin/configure.php, (8) find parameter in (f) admin/users.php, (9) start parameter in (g) admin/admin.php, and (10) action parameter in (h) admin/fckphplist.php.

    Published: 16 Nov 2005
    5
    Medium

    CVE-2005-3557

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in admin/defaults.php in PHPlist 2.10.1 and earlier allows remote attackers to access arbitrary files via a .. (dot dot) in the selected%5B%5D parameter in an HTTP POST request.

    Published: 16 Nov 2005
    7.5
    High

    CVE-2005-3560

    Last Modified: 16 Apr 2026

    Zone Labs (1) ZoneAlarm Pro 6.0, (2) ZoneAlarm Internet Security Suite 6.0, (3) ZoneAlarm Anti-Virus 6.0, (4) ZoneAlarm Anti-Spyware 6.0 through 6.1, and (5) ZoneAlarm 6.0 allow remote attackers to bypass the "Advanced Program Control and OS Firewall filters" setting via URLs in "HTML Modal Dialogs" (window.location.href) contained within JavaScript tags.

    Published: 16 Nov 2005
    7.5
    High

    CVE-2005-3572

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in Peel 2.6 through 2.7 allows remote attackers to execute arbitrary SQL commands via the rubid parameter.

    Published: 16 Nov 2005
    7.5
    High

    CVE-2005-3578

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary SQL commands via the sug parameter.

    Published: 16 Nov 2005
    5
    Medium

    CVE-2005-3579

    Last Modified: 16 Apr 2026

    ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to access arbitrary local files via the querystring.

    Published: 16 Nov 2005
    7.2
    High

    CVE-2005-3582

    Last Modified: 16 Apr 2026

    ImageMagick before 6.2.4.2-r1 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.

    Published: 16 Nov 2005
    7.5
    High

    CVE-2005-3588

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in admin.php in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the username field.

    Published: 16 Nov 2005
    10
    Critical

    CVE-2005-3595

    Last Modified: 16 Apr 2026

    By default Microsoft Windows XP Home Edition installs with a blank password for the Administrator account, which allows remote attackers to gain control of the computer.

    Published: 16 Nov 2005
    Unknown

    CVE-2005-3562

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-2955. Reason: This candidate is a reservation duplicate of CVE-2005-2955. Notes: All CVE users should reference CVE-2005-2955 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 16 Nov 2005
    7.5
    High

    CVE-2005-3565

    Last Modified: 16 Apr 2026

    Unknown vulnerability in remshd daemon in HP-UX B.11.00, B.11.11, and B.11.23 while running in "Trusted Mode" allows remote attackers to gain unauthorized system access via unknown attack vectors.

    Published: 16 Nov 2005
    2.1
    Low

    CVE-2005-3568

    Last Modified: 16 Apr 2026

    db2fmp process in IBM DB2 Content Manager before 8.2 Fix Pack 10 allows local users to cause a denial of service (CPU consumption) by importing a corrupted Microsoft Excel file, aka "CORRUPTED EXEL FILE WILL CAUSE TEXT SEARCH PROCESS LOOPING."

    Published: 16 Nov 2005
    4.3
    Medium

    CVE-2005-3570

    Last Modified: 16 Apr 2026

    Unspecified cross-site scripting (XSS) vulnerability in Horde before 2.2.9 allows remote attackers to inject arbitrary web script or HTML via "not properly escaped error messages".

    Published: 16 Nov 2005
    10
    Critical

    CVE-2005-3587

    Last Modified: 16 Apr 2026

    Improper boundary checks in petite.c in Clam AntiVirus (ClamAV) before 0.87.1 allows attackers to perform unknown attacks via unknown vectors.

    Published: 16 Nov 2005
    7.8
    High

    CVE-2005-2975

    Last Modified: 16 Apr 2026

    io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a crafted XPM image with a large number of colors.

    Published: 15 Nov 2005
    7.5
    High

    CVE-2005-2976

    Last Modified: 16 Apr 2026

    Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a denial of service (crash) or execute arbitrary code via an XPM file with large height, width, and colour values, a different vulnerability than CVE-2005-3186.

    Published: 15 Nov 2005
    4.9
    Medium

    CVE-2005-3857

    Last Modified: 16 Apr 2026

    The time_out_leases function in locks.c for Linux kernel before 2.6.15-rc3 allows local users to cause a denial of service (kernel log message consumption) by causing a large number of broken leases, which is recorded to the log using the printk function.

    Published: 13 Nov 2005
    4.6
    Medium

    CVE-2005-3662

    Last Modified: 16 Apr 2026

    Off-by-one buffer overflow in pnmtopng before 2.39, when using the -alpha command line option (Alphas_Of_Color), allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PNM file with exactly 256 colors.

    Published: 12 Nov 2005
    4.6
    Medium

    CVE-2005-3632

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in pnmtopng in netpbm 10.0 and earlier allow attackers to execute arbitrary code via a crafted PNM file.

    Published: 12 Nov 2005
    7.5
    High

    CVE-2005-2929

    Last Modified: 16 Apr 2026

    Lynx 2.8.5, and other versions before 2.8.6dev.15, allows remote attackers to execute arbitrary commands via (1) lynxcgi:, (2) lynxexec, and (3) lynxprog links, which are not properly restricted in the default configuration in some environments.

    Published: 11 Nov 2005
    5.1
    Medium

    CVE-2005-2629

    Last Modified: 16 Apr 2026

    Integer overflow in RealNetworks RealPlayer 8, 10, and 10.5, RealOne Player 1 and 2, and Helix Player 10.0.0 allows remote attackers to execute arbitrary code via an .rm movie file with a large value in the length field of the first data packet, which leads to a stack-based buffer overflow, a different vulnerability than CVE-2004-1481.

    Published: 10 Nov 2005
    4.9
    Medium

    CVE-2005-3784

    Last Modified: 16 Apr 2026

    The auto-reap of child processes in Linux kernel 2.6 before 2.6.15 includes processes with ptrace attached, which leads to a dangling ptrace reference and allows local users to cause a denial of service (crash) and gain root privileges.

    Published: 10 Nov 2005
    4
    Medium

    CVE-2005-3527

    Last Modified: 16 Apr 2026

    Race condition in do_coredump in signal.c in Linux kernel 2.6 allows local users to cause a denial of service by triggering a core dump in one thread while another thread has a pending SIGSTOP.

    Published: 9 Nov 2005
    4.6
    Medium

    CVE-2005-2709

    Last Modified: 16 Apr 2026

    The sysctl functionality (sysctl.c) in Linux kernel before 2.6.14.1 allows local users to cause a denial of service (kernel oops) and possibly execute code by opening an interface file in /proc/sys/net/ipv4/conf/, waiting until the interface is unregistered, then obtaining and modifying function pointers in memory that was used for the ctl_table.

    Published: 8 Nov 2005
    7.5
    High

    CVE-2005-3523

    Last Modified: 16 Apr 2026

    Format string vulnerability in friendsd2 in GpsDrive allows remote attackers to execute arbitrary code via the dir (direction) field.

    Published: 7 Nov 2005
    10
    Critical

    CVE-2005-3524

    Last Modified: 16 Apr 2026

    Buffer overflow in the SSL-ready version of linux-ftpd (linux-ftpd-ssl) 0.17 allows remote attackers to execute arbitrary code by creating a long directory name, then executing the XPWD command.

    Published: 7 Nov 2005
    3.7
    Low

    CVE-2005-4268

    Last Modified: 16 Apr 2026

    Buffer overflow in cpio 2.6-8.FC4 on 64-bit platforms, when creating a cpio archive, allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a file whose size is represented by more than 8 digits.

    Published: 7 Nov 2005
    5
    Medium

    CVE-2005-3507

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" sequences in the template parameter to (1) show_archives.php and (2) show_news.php.

    Published: 6 Nov 2005
    7.5
    High

    CVE-2005-3508

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in showGallery.php in Gallery (Galerie) 2.4 allows remote attackers to execute arbitrary SQL commands via the galid parameter.

    Published: 6 Nov 2005
    7.5
    High

    CVE-2005-3509

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in JPortal allow remote attackers to execute arbitrary SQL commands via (1) banner.php or the id parameter to (2) print.php, (3) comment.php, and (4) news.php.

    Published: 6 Nov 2005
    4.3
    Medium

    CVE-2005-3516

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk Directory script allows remote attackers to inject arbitrary web script or HTML via the entryID parameter.

    Published: 6 Nov 2005
    5
    Medium

    CVE-2005-3517

    Last Modified: 16 Apr 2026

    Chipmunk Scripts Guestbook allows remote attackers to obtain the installation path of the script via a URL that causes an error message to be displayed, such as a URL that contains a single quote (') in the start parameter of index.php.

    Published: 6 Nov 2005
    7.5
    High

    CVE-2005-3518

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search.php in PunBB 1.2.7 and 1.2.8 allows remote attackers to execute arbitrary SQL commands via the old_searches parameter.

    Published: 6 Nov 2005
    4.3
    Medium

    CVE-2005-3522

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.jsp in ManageEngine Netflow Analyzer 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the grDisp parameter.

    Published: 6 Nov 2005
    2.1
    Low

    CVE-2005-3124

    Last Modified: 16 Apr 2026

    syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file.

    Published: 6 Nov 2005
    4.3
    Medium

    CVE-2005-3511

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Spymac Web OS 4.0 allow remote attackers to inject arbitrary web script or HTML via (a) the blogs module, including the (1) curr parameter in index.php, (2) inspire, (3) system, or (4) title parameter in blog_newentry.php, (5) entry parameter in blog_newentry_comment.php, (6) entry parameter in blog_edit_entry.php, or (7) caldate parameter in blog.php; and (b) the notes module, including the (1) forwardid parameter in a noteform action; (2) del_folder parameter in a delete_folder action; (3) isread, (4) dateorder, (5) subjectorder, (6) curr, (7) fromorder, or (8) action parameters; (9) ppp or (10) totalreplies parameter in an Inbox action; (11) totalnotes parameter; or (12) touserid parameter in a noteform action.

    Published: 6 Nov 2005
    5
    Medium

    CVE-2005-3513

    Last Modified: 16 Apr 2026

    index.php in VUBB alpha rc1 allows remote attackers to obtain the installation path of the application via a viewforum action with the f parameter set to a single quote (').

    Published: 6 Nov 2005
    4.3
    Medium

    CVE-2005-3515

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk Topsites script allows remote attackers to inject arbitrary web script or HTML via the ID parameter.

    Published: 6 Nov 2005
    7.5
    High

    CVE-2005-3521

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in resetcore.php in e107 0.617 through 0.6173 allows remote attackers to execute arbitrary SQL commands, bypass authentication, and inject HTML or script via the (1) a_name parameter or (2) user field of the login page.

    Published: 6 Nov 2005
    4.3
    Medium

    CVE-2005-3512

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in VUBB alpha rc1 allows remote attackers to inject arbitrary web script or HTML via the t parameter in a newreply action.

    Published: 6 Nov 2005
    4.3
    Medium

    CVE-2005-3514

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Forum script allow remote attackers to inject arbitrary web script or HTML via the forumID parameter to (1) newtopic.php, (2) quote.php, (3) index.php, and (4) reply.php.

    Published: 6 Nov 2005
    7.5
    High

    CVE-2005-3519

    Last Modified: 16 Apr 2026

    Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and include arbitrary local files via the (1) INCLUDE_PATH and (2) SQUIZLIB_PATH parameters in new_upgrade_functions.php, (3) the INCLUDE_PATH parameter in init_mysource.php, and the PEAR_PATH parameter in (4) Socket.php, (5) Request.php, (6) Mail.php, (7) Date.php, (8) Span.php, (9) mimeDecode.php, and (10) mime.php.

    Published: 6 Nov 2005
    4.3
    Medium

    CVE-2005-3520

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web script or HTML via (1) the target_url parameter in upgrade_in_progress_backend.php, (2) the stylesheet parameter in edit_table_cell_type_wysiwyg.php, and the bgcolor parameter in (3) insert_table.php, (4) edit_table_cell_props.php, (5) header.php, (6) edit_table_row_props.php, and (7) edit_table_props.php.

    Published: 6 Nov 2005
    5.1
    Medium

    CVE-2005-2753

    Last Modified: 16 Apr 2026

    Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file that causes a sign extension of the length element in a Pascal style string.

    Published: 5 Nov 2005
    5.1
    Medium

    CVE-2005-2754

    Last Modified: 16 Apr 2026

    Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file with "Improper movie attributes."

    Published: 5 Nov 2005
    2.6
    Low

    CVE-2005-2755

    Last Modified: 16 Apr 2026

    Apple QuickTime Player before 7.0.3 allows user-assisted attackers to cause a denial of service (crash) via a crafted file with a missing movie attribute, which leads to a null dereference.

    Published: 5 Nov 2005
    5.1
    Medium

    CVE-2005-2756

    Last Modified: 16 Apr 2026

    Apple QuickTime before 7.0.3 allows user-assisted attackers to overwrite memory and execute arbitrary code via a crafted PICT file that triggers an overflow during expansion.

    Published: 5 Nov 2005
    7.5
    High

    CVE-2005-3303

    Last Modified: 16 Apr 2026

    The FSG unpacker (fsg.c) in Clam AntiVirus (ClamAV) 0.80 through 0.87 allows remote attackers to cause "memory corruption" and execute arbitrary code via a crafted FSG 1.33 file.

    Published: 5 Nov 2005
    5
    Medium

    CVE-2005-3500

    Last Modified: 16 Apr 2026

    The tnef_attachment function in tnef.c for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via a crafted value in a CAB file that causes ClamAV to repeatedly scan the same block.

    Published: 5 Nov 2005