CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2005-3501

    Last Modified: 16 Apr 2026

    The cabd_find function in cabd.c of the libmspack library (mspack) for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted CAB file that causes cabd_find to be called with a zero length.

    Published: 5 Nov 2005
    5
    Medium

    CVE-2005-3502

    Last Modified: 16 Apr 2026

    attachment_send.php in Cerberus Helpdesk allows remote attackers to view attachments and tickets of other users via a modified file_id parameter.

    Published: 5 Nov 2005
    7.2
    High

    CVE-2005-3503

    Last Modified: 16 Apr 2026

    chfn in pwdutils 3.0.4 and earlier on SuSE Linux, and possibly other operating systems, does not properly check arguments for the GECOS field, which allows local users to gain privileges.

    Published: 5 Nov 2005
    7.5
    High

    CVE-2005-3504

    Last Modified: 16 Apr 2026

    Buffer overflow in swcons in IBM AIX 5.2, when debug malloc is enabled, allows remote attackers to cause a core dump and possibly execute arbitrary code.

    Published: 5 Nov 2005
    4.3
    Medium

    CVE-2005-3505

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Entropy Chat script in cPanel 10.2.0-R82 and 10.6.0-R137 allows remote attackers to inject arbitrary web script or HTML via a chat message containing Javascript in style attributes in tags such as <b>, which are processed by Internet Explorer.

    Published: 5 Nov 2005
    4.3
    Medium

    CVE-2005-3506

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in proxy.asp in Sambar Server 6.3 BETA 2 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the (1) Remote Proxy Server or (2) Proxy Filter IPs field.

    Published: 5 Nov 2005
    5
    Medium

    CVE-2005-3492

    Last Modified: 16 Apr 2026

    FlatFrag 0.3 and earlier allows remote attackers to cause a denial of service (crash) by sending an NT_CONN_OK command from a client that is not connected, which triggers a null dereference.

    Published: 4 Nov 2005
    5
    Medium

    CVE-2005-3493

    Last Modified: 16 Apr 2026

    Battle Carry .005 and earlier allows remote attackers to cause a denial of service (inaccessible port) via a large packet, which triggers a socket error and terminates the socket that is listening on the server's UDP port.

    Published: 4 Nov 2005
    4.3
    Medium

    CVE-2005-3494

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Ar-blog 5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a blog comment.

    Published: 4 Nov 2005
    7.5
    High

    CVE-2005-3495

    Last Modified: 16 Apr 2026

    Ar-blog 5.2 and earlier allows remote attackers to bypass authentication by modifying cookies.

    Published: 4 Nov 2005
    5.1
    Medium

    CVE-2005-2628

    Last Modified: 16 Apr 2026

    Macromedia Flash 6 and 7 (Flash.ocx) allows remote attackers to execute arbitrary code via a SWF file with a modified frame type identifier that is used as an out-of-bounds array index to a function pointer.

    Published: 4 Nov 2005
    5
    Medium

    CVE-2005-3490

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the web server in Asus Video Security 3.5.0.0 and earlier allows remote attackers to read arbitrary files via "../" or "..\" sequences in the URL.

    Published: 4 Nov 2005
    7.5
    High

    CVE-2005-3491

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the receiver function in loop.c in FlatFrag 0.3 and earlier allow remote attackers to execute arbitrary code via the (1) version, (2) name, and (3) model fields.

    Published: 4 Nov 2005
    4.3
    Medium

    CVE-2005-3498

    Last Modified: 16 Apr 2026

    IBM WebSphere Application Server 5.0.x before 5.02.15, 5.1.x before 5.1.1.8, and 6.x before fixpack V6.0.2.5, when session trace is enabled, records a full URL including the queryString in the trace logs when an application encodes a URL, which could allow attackers to obtain sensitive information.

    Published: 4 Nov 2005
    7.5
    High

    CVE-2005-3499

    Last Modified: 16 Apr 2026

    Frisk F-Prot Antivirus allows remote attackers to bypass protection via a ZIP file with a version header greater than 15, which prevents F-Prot from decompressing and analyzing the file.

    Published: 4 Nov 2005
    7.5
    High

    CVE-2005-3489

    Last Modified: 16 Apr 2026

    Buffer overflow in Asus Video Security 3.5.0.0 and earlier, when using authorization, allows remote attackers to execute arbitrary code via a long username/password string.

    Published: 4 Nov 2005
    4.3
    Medium

    CVE-2005-3496

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in PHP Handicapper allows remote attackers to inject arbitrary web script or HTML via the msg parameter to msg.php. NOTE: some sources identify a second vector in the login parameter to process_signup.php, but the original source says that it is for CRLF injection (CVE-2005-4712). Also note: the vendor has disputed CVE-2005-3497, and it is possible that the dispute was intended to include this issue as well. If so, followup investigation strongly suggests that the original report is correct.

    Published: 4 Nov 2005
    7.5
    High

    CVE-2005-3497

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in process_signup.php in PHP Handicapper allows remote attackers to execute arbitrary SQL commands via the serviceid parameter. NOTE: on 20060210, the vendor disputed this issue, saying "this is 100% false reporting, this is a slander campaign from a customer who had a vulnerability in his SERVER not the software." However, followup investigation strongly suggests that the original report is correct

    Published: 4 Nov 2005
    7.5
    High

    CVE-2005-3483

    Last Modified: 16 Apr 2026

    Buffer overflow in GO-Global for Windows 3.1.0.3270 and earlier allows remote attackers to execute arbitrary code via a data block that is longer than the specified data block size.

    Published: 3 Nov 2005
    5
    Medium

    CVE-2005-3484

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in NeroNET 1.2.0.2 and earlier allows remote attackers to read arbitrary files with certain file extensions (such as ZIP, AVI, JPG, TXT, and HTML) via ".." and hex-encoded (1) slash "/" ("%2f") or (2) backslash "\" ("%5c") sequences.

    Published: 3 Nov 2005
    7.5
    High

    CVE-2005-3485

    Last Modified: 16 Apr 2026

    Buffer overflow in Glider Collect'n kill 1.0.0.0 allows remote attackers to execute arbitrary code via a gl_playerEnter command with a long player name.

    Published: 3 Nov 2005
    7.5
    High

    CVE-2005-3486

    Last Modified: 16 Apr 2026

    Multiple format string vulnerabilities in Scorched 3D 39.1 (bf) and earlier allow remote attackers to execute arbitrary code via various (1) GLConsole::addLine, (2) ServerCommon::sendString, (3) ServerCommon::serverLog functions, and possibly other unspecified vectors.

    Published: 3 Nov 2005
    7.8
    High

    CVE-2005-3488

    Last Modified: 16 Apr 2026

    Scorched 3D 39.1 (bf) and earlier allows remote attackers to cause a denial of service (long loop and server hang) via a negative numplayers value that bypasses a signed check in ServerConnectHandler.cpp.

    Published: 3 Nov 2005
    7.5
    High

    CVE-2005-3487

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Scorched 3D 39.1 (bf) and earlier allow remote attackers to execute arbitrary code via various (1) GLConsole::addLine, (2) ServerCommon::sendString, (3) ServerCommon::serverLog functions, (4) a long command that is not properly handled in ComsMessageHandler.cpp when generating an error message, (5) a long UniqueID value in Logger.cpp, and possibly other unspecified vectors.

    Published: 3 Nov 2005
    5
    Medium

    CVE-2005-3472

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Sun Java System Communications Express 2005Q1 and 2004Q2 allows local and remote attackers to read sensitive information from configuration files.

    Published: 3 Nov 2005
    5
    Medium

    CVE-2005-3475

    Last Modified: 16 Apr 2026

    Hasbani Web Server (WindWeb) 2.0 allows remote attackers to cause a denial of service (infinite loop) via HTTP crafted GET requests.

    Published: 3 Nov 2005
    2.1
    Low

    CVE-2005-3476

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in HP OpenVMS Integrity 8.2-1 and 8.2, and OpenVMS Alpha 7.3-2 and 8.2, allows local users to cause a denial of service.

    Published: 3 Nov 2005
    7.5
    High

    CVE-2005-3478

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in PHPCafe.net Tutorials Manager 1.0 Beta 2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 3 Nov 2005
    4.3
    Medium

    CVE-2005-3479

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in login.asp in Ringtail CaseBook 6.1.0 allows remote attackers to inject arbitrary web script or HTML via the users parameter.

    Published: 3 Nov 2005
    5
    Medium

    CVE-2005-3480

    Last Modified: 16 Apr 2026

    login.asp in Ringtail CaseBook 6.1.0 displays different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames.

    Published: 3 Nov 2005
    4.3
    Medium

    CVE-2005-3473

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog 0.4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entry, (2) blog_subject, and (3) blog_text parameters (involving the temp_subject variable) in (a) preview_cgi.php and (b) preview_static_cgi.php, or (4) scheme_name parameter and (5) bg_color parameters (involving the preset_name and result variables) in (c) colors.php.

    Published: 3 Nov 2005
    4.6
    Medium

    CVE-2005-3474

    Last Modified: 16 Apr 2026

    The aries.sys driver in Sony First4Internet XCP DRM software hides any file, registry key, or process with a name that starts with "$sys$", which allows attackers to hide activities on a system that uses XCP.

    Published: 3 Nov 2005
    4.3
    Medium

    CVE-2005-3477

    Last Modified: 16 Apr 2026

    Multiple interpretation error in the image upload handling code in Invision Gallery 2.0.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML or script in an image whose type does not match its extension, which is rendered by Internet Explorer due to CVE-2005-3312. NOTE: it could be argued that this vulnerability is due to a design flaw in Internet Explorer and the proper fix should be in that browser; if so, then this should not be treated as a vulnerability in Invision Gallery.

    Published: 3 Nov 2005
    5
    Medium

    CVE-2005-3482

    Last Modified: 16 Apr 2026

    Cisco 1200, 1131, and 1240 series Access Points, when operating in Lightweight Access Point Protocol (LWAPP) mode and controlled by 2000 and 4400 series Airespace WLAN controllers running 3.1.59.24, allow remote attackers to send unencrypted traffic to a secure network using frames with the MAC address of an authenticated end host.

    Published: 3 Nov 2005
    9.3
    Critical

    CVE-2005-3481

    Last Modified: 16 Apr 2026

    Cisco IOS 12.0 to 12.4 might allow remote attackers to execute arbitrary code via a heap-based buffer overflow in system timers. NOTE: this issue does not correspond to a specific vulnerability, rather a general weakness that only increases the feasibility of exploitation of any vulnerabilities that might exist. Such design-level weaknesses normally are not included in CVE, so perhaps this issue should be REJECTed.

    Published: 3 Nov 2005
    2.6
    Low

    CVE-2005-2974

    Last Modified: 16 Apr 2026

    libungif library before 4.1.0 allows attackers to cause a denial of service via a crafted GIF file that triggers a null dereference.

    Published: 3 Nov 2005
    7.5
    High

    CVE-2005-3350

    Last Modified: 16 Apr 2026

    libungif library before 4.1.0 allows attackers to corrupt memory and possibly execute arbitrary code via a crafted GIF file that leads to an out-of-bounds write.

    Published: 3 Nov 2005
    5
    Medium

    CVE-2005-3510

    Last Modified: 16 Apr 2026

    Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous requests to list a web directory that has a large number of files.

    Published: 3 Nov 2005
    7.5
    High

    CVE-2005-3186

    Last Modified: 16 Apr 2026

    Integer overflow in the GTK+ gdk-pixbuf XPM image rendering library in GTK+ 2.4.0 allows attackers to execute arbitrary code via an XPM file with a number of colors that causes insufficient memory to be allocated, which leads to a heap-based buffer overflow.

    Published: 3 Nov 2005
    5
    Medium

    CVE-2005-3468

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in F-Secure Anti-Virus for Microsoft Exchange 6.40 and Internet Gatekeeper 6.40 to 6.42 allows limited remote attackers to bypass Web Console authentication and read files.

    Published: 2 Nov 2005
    7.5
    High

    CVE-2005-3469

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in News2Net 3.0.0.0 allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Published: 2 Nov 2005
    7.5
    High

    CVE-2005-3470

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in in the authenticate function in MailWatch for MailScanner 1.0.2 allows remote attackers to execute arbitrary SQL commands.

    Published: 2 Nov 2005
    5
    Medium

    CVE-2005-3471

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the ruleset view for MailWatch for MailScanner 1.0.2 allows remote attackers to access arbitrary files.

    Published: 2 Nov 2005
    5
    Medium

    CVE-2005-3467

    Last Modified: 16 Apr 2026

    Serv-U FTP Server before 6.1.0.4 allows attackers to cause a denial of service (crash) via (1) malformed packets and possibly other unspecified issues with unknown impact and attack vectors including (2) use of "~" in a pathname, and (3) memory consumption of the daemon. NOTE: it is not clear whether items (2) and above are vulnerabilities.

    Published: 2 Nov 2005
    5
    Medium

    CVE-2005-3431

    Last Modified: 16 Apr 2026

    Absolute path traversal vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to read arbitrary files via a full pathname in the AttachPath field of a mail message under composition.

    Published: 2 Nov 2005
    7.5
    High

    CVE-2005-3434

    Last Modified: 16 Apr 2026

    Archilles Newsworld before 1.5.0-rc1 stores (1) account.nwd and (2) session.nwd under the web root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames, hashed passwords, and session IDs, and gain privileges.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3437

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the PL/SQL component in Oracle Database Server 9i up to 10.1.0.4 has unknown impact and attack vectors, aka Oracle Vuln# DB01.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3440

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Database Scheduler in Oracle Database Server 10g up to 10.1.0.3 has unknown impact and attack vectors, aka Oracle Vuln# DB08.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3441

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Intelligent Agent in Oracle Database Server 9i up to 9.0.1.5 has unknown impact and attack vectors, aka Oracle Vuln# DB14.

    Published: 2 Nov 2005
    4.3
    Medium

    CVE-2005-3436

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Nuked-Klan 1.7 allows remote attackers to inject arbitrary web script or HTML via the (1) Search module, (2) certain edit fields in Guestbook, (3) the title in the Forum module, and (4) Textbox.

    Published: 2 Nov 2005