CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2005-3446

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Internet Directory in Oracle Database Server 9i up to 9.2.0.6 and Application Server 9.0.2.3 up to 10.1.2.0 has unknown impact and attack vectors, aka Oracle Vuln# DB32 and AS06.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3447

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Single Sign-On in Oracle Database Server 10g up to 10.1.0.4.2 and Application Server 9.0.2.3 up to 9.0.4.2 has unknown impact and attack vectors, aka Oracle Vuln# DB33 and AS08.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3448

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the OC4J Module in Oracle Application Server 9.0 up to 10.1.2.0.2 has unknown impact and attack vectors, as identified by Oracle Vuln# AS01.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3450

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the HTTP Server in Oracle Application Server 1.0 up to 9.0.2.3 has unknown impact and attack vectors, as identified by Oracle Vuln# AS04.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3456

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5 up to 11.5.9 have unknown impact and attack vectors, as identified by Oracle Vuln# (1) APPS04 in Application Object Library, and (2) APPS17, (3) APPS18, and (4) APPS21 in Workflow Cartridge.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3457

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Oracle E-Business Suite and Applications 11.0 up to 11.5.10 has unknown impact and attack vectors, as identified by Oracle Vuln# APPS08 in HRMS.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3461

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in PeopleTools in Oracle PeopleSoft Enterprise 8.42 up to 8.45.17 has unknown impact and attack vectors, as identified by Oracle Vuln# PSE01.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3462

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in PeopleTools in Oracle PeopleSoft Enterprise 8.44 up to 8.46.02 has unknown impact and attack vectors, as identified by Oracle Vuln# PSE02.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3463

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in PeopleTools in Oracle PeopleSoft Enterprise 8.44 up to 8.46.03 has unknown impact and attack vectors, as identified by Oracle Vuln# PSE03.

    Published: 2 Nov 2005
    9.8
    Critical

    CVE-2005-3435

    Last Modified: 16 Apr 2026

    admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for example through another Newsworld vulnerability, and specifying the hash in the pwd argument.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3438

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Database Server 9i up to 10.1.0.4.2 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB04 in Change Data Capture; (2) DB06 in Data Guard Logical Standby; (3) DB10 in Locale; (4) DB12 in Materialized Views; (5) DB13 in Objects Extension; (6) DB15 in Oracle Label Security; (7) DB27 in Security, possibly due to a buffer overflow in sys.pbsde.init; and (8) DB28 and (9) DB29 in Workspace Manager.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3453

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Web Cache in Oracle Application Server 1.0 up to 10.1.2.0 has unknown impact and attack vectors, as identified by Oracle Vuln# (1) AS12 and (2) AS14.

    Published: 2 Nov 2005
    4.3
    Medium

    CVE-2005-3428

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to inject arbitrary web script or HTML via a message body.

    Published: 2 Nov 2005
    7.5
    High

    CVE-2005-3430

    Last Modified: 16 Apr 2026

    Incomplete blacklist vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions, such as (1) .unk, (2) .asa, and possibly (3) .htr and (4) .aspx, which are not filtered like the .asp extension.

    Published: 2 Nov 2005
    5.1
    Medium

    CVE-2005-3433

    Last Modified: 16 Apr 2026

    Buffer overflow in Mirabilis ICQ 2003a allows user-assisted attackers to execute arbitrary code by convincing a user to enter long strings into the First Name and Last Name fields.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3439

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Database Server 10g up to 10.1.0.4.2 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB02, (2) DB03, and (3) DB05 in Change Data Capture; (4) DB07 in Data Pump Export; and (5) DB18, (6) DB19, (7) DB20, (8) DB21, (9) DB22, (10) DB23, (11) DB24, and (12) DB25 in the Spatial component.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3442

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Database Server 8i up to 10.1.0.4.2 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB09 in Export, (2) DB11 in Materialized Views, and (3) DB16 in Security Service.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3444

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in the Programmatic Interface in Oracle Database Server from 8i up to 9.2.0.5 have unknown impact and attack vectors, aka Oracle Vuln# DB26.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3445

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in HTTP Server in Oracle Database Server 8i up to 10.1.0.4.2 and Application Server 1.0.2.2 up to 10.1.2.0 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB30 and AS03 or (2) DB31 and AS05.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3449

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Application Server 9.0 up to 10.1.2.0 have unknown impact and attack vectors, as identified by Oracle Vuln# (1) AS02 in Containers for J2EE, (2) AS07 in Internet Directory, (3) AS09 in Report Server, and (4) AS11 in Web Cache.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3452

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Web Cache in Oracle Application Server 1.0 up to 9.0.4.2 has unknown impact and attack vectors, as identified by Oracle Vuln# AS13.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3455

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5 up to 11.5.10 have unknown impact and attack vectors, as identified by Oracle Vuln# (1) APPS01 in Application Install; (2) APPS02 and (3) APPS03 in Application Object Library; (4) APPS05 and (5) APPS06 in Applications Technology Stack; (6) APPS07 in Applications Utilities; (7) APPS09, (8) APPS10, and (9) APPS11 in HRMS; (10) APPS12 in Mobile Application Foundation; (11) APPS13 in SDP Number Portability; (12) APPS14 in Oracle Service; (13) APPS15 in Service Fulfillment Manage, (14) APPS16 in Universal Work Queue; and (15) APPS20 in Workflow Cartridge.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3458

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Oracle E-Business Suite and Applications 11.0 up to 11.5.9 has unknown impact and attack vectors, as identified by Oracle Vuln# APPS19 in Workflow Cartridge.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3459

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Oracle E-Business Suite and Applications 4.5 up to 4.5.1 has unknown impact and attack vectors, as identified by Oracle Vuln# APPS22 in Oracle Clinical.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3465

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in JDEdwards HTML Server in Oracle EnterpriseOne 8.94 OneWorld XE up to 8.95_B1, 8.94_Q1, and SP23_K1 has unknown impact and attack vectors, as identified by Oracle Vuln# JDE01.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3466

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Enterprise CRM Sales in Oracle 8.81 up to 8.9 has unknown impact and attack vectors, as identified by Oracle Vuln# CRM01.

    Published: 2 Nov 2005
    5
    Medium

    CVE-2005-3432

    Last Modified: 16 Apr 2026

    MiniGal 2 (MG2) 0.5.1 allows remote attackers to list password protected images via a request to index.php with the list parameter set to * (wildcard) and the page parameter set to all.

    Published: 2 Nov 2005
    4.3
    Medium

    CVE-2005-3429

    Last Modified: 16 Apr 2026

    Rockliffe MailSite Express before 6.1.22, with the option to save login information enabled, saves user passwords in plaintext in cookies, which allows local users to obtain passwords by reading the cookie file, or remote attackers to obtain the cookies via cross-site scripting (XSS) vulnerabilities.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3443

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the Spatial component in Oracle Database Server from 9i up to 10.1.0.3 has unknown impact and attack vectors, aka Oracle Vuln# DB17.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3451

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in SQL*ReportWriter in Oracle Application Server 9.0 up to 9.0.2.1 has unknown impact and attack vectors, as identified by Oracle Vuln# AS10.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3454

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Collaboration Suite 10g Release 1 version 10.1.1 and 9i Release 2 9.0.4.2 have unknown impact and attack vectors, as identified by Oracle Vuln# (1) OCS01, (2) OCS02, (3) OCS03, and (4) OCS04 for Calendar; (5) OCS05, (6) OCS06, (7) OCS07, (8) OCS08, (9) OCS09, and (10) OCS10 for Email Server; and (11) OCS11, (12) OCS12, and (13) OCS13 for Oracle Files.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3460

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Oracle Agent in Oracle Enterprise Manager 9.0.4.1 up to 10.1.0.4 has unknown impact and attack vectors, as identified by Oracle Vuln# EM01.

    Published: 2 Nov 2005
    10
    Critical

    CVE-2005-3464

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in PeopleTools in Oracle PeopleSoft Enterprise 8.44 up to 8.46 has unknown impact and attack vectors, as identified by Oracle Vuln# PSE04.

    Published: 2 Nov 2005
    5
    Medium

    CVE-2005-3426

    Last Modified: 16 Apr 2026

    Cisco CSS 11500 Content Services Switch (CSS) with SSL termination services allows remote attackers to cause a denial of service (memory corruption and device reload) via a malformed client certificate during SSL session negotiation.

    Published: 2 Nov 2005
    5
    Medium

    CVE-2009-3387

    Last Modified: 11 Apr 2025

    Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process of moving a bug to a different product category, which allows remote attackers to obtain sensitive information via a request for a bug in opportunistic circumstances.

    Published: 2 Nov 2005
    4.3
    Medium

    CVE-2009-3989

    Last Modified: 11 Apr 2025

    Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.

    Published: 2 Nov 2005
    5
    Medium

    CVE-2005-3409

    Last Modified: 16 Apr 2026

    OpenVPN 2.x before 2.0.4, when running in TCP mode, allows remote attackers to cause a denial of service (segmentation fault) by forcing the accept function call to return an error status, which leads to a null dereference in an exception handler.

    Published: 2 Nov 2005
    2.1
    Low

    CVE-2005-3427

    Last Modified: 16 Apr 2026

    The Cisco Management Center (MC) for IPS Sensors (IPS MC) 2.1 can omit port field values while generating the Cisco IOS IPS configuration file, wich can cause some signatures to be disabled and makes it easier for attackers to escape detection.

    Published: 2 Nov 2005
    7.5
    High

    CVE-2005-3423

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Subdreamer 2.2.1 allow remote attackers to execute arbitrary SQL commands via (1) the loginusername parameter or (2) cookies to (a) subdreamer.php, (b) ipb2.php, (c) phpbb2.php, (d) vbulletin2.php, and (e) vbulletin3.php.

    Published: 1 Nov 2005
    4.3
    Medium

    CVE-2005-3424

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in GNUMP3D before 2.9.5 allows remote attackers to inject arbitrary web script or HTML via 404 error pages, a different vulnerability than CVE-2005-3425.

    Published: 1 Nov 2005
    4.3
    Medium

    CVE-2005-3425

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in GNUMP3D before 2.9.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2005-3424.

    Published: 1 Nov 2005
    7.5
    High

    CVE-2005-3417

    Last Modified: 16 Apr 2026

    phpBB 2.0.17 and earlier, when the register_long_arrays directive is disabled, allows remote attackers to modify global variables and bypass security mechanisms because PHP does not define the associated HTTP_* variables.

    Published: 1 Nov 2005
    4.3
    Medium

    CVE-2005-3418

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.17 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) error_msg parameter to usercp_register.php, (2) forward_page parameter to login.php, and (3) list_cat parameter to search.php, which are not initialized as variables.

    Published: 1 Nov 2005
    5
    Medium

    CVE-2005-3421

    Last Modified: 16 Apr 2026

    estcmd in Hyper Estraier 1.0.1 on Windows systems allows remote attackers to read unauthorized files via a crafted search request for a filename that contains Unicode characters.

    Published: 1 Nov 2005
    4.3
    Medium

    CVE-2005-3422

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in error.asp in ASP Fast Forum allows remote attackers to inject arbitrary web script or HTML via the error parameter.

    Published: 1 Nov 2005
    7.5
    High

    CVE-2005-3420

    Last Modified: 16 Apr 2026

    usercp_register.php in phpBB 2.0.17 allows remote attackers to modify regular expressions and execute PHP code via the signature_bbcode_uid parameter, as demonstrated by injecting an "e" modifier into a preg_replace statement.

    Published: 1 Nov 2005
    7.5
    High

    CVE-2005-3416

    Last Modified: 16 Apr 2026

    phpBB 2.0.17 and earlier, when register_globals is enabled and the session_start function has not been called to handle a session, allows remote attackers to bypass security checks by setting the $_SESSION and $HTTP_SESSION_VARS variables to strings instead of arrays, which causes an array_merge function call to fail.

    Published: 1 Nov 2005
    7.5
    High

    CVE-2005-3415

    Last Modified: 16 Apr 2026

    phpBB 2.0.17 and earlier allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GET/POST/COOKIE (GPC) variable and a GLOBALS[] variable with the same name, which causes phpBB to unset the GLOBALS[] variable but not the GPC variable.

    Published: 1 Nov 2005
    7.5
    High

    CVE-2005-3419

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in usercp_register.php in phpBB 2.0.17 allows remote attackers to execute arbitrary SQL commands via the signature_bbcode_uid parameter, which is not properly initialized.

    Published: 1 Nov 2005
    7.5
    High

    CVE-2005-3414

    Last Modified: 16 Apr 2026

    eyeOS 0.8.4 stores usrinfo.xml under the web document root with insufficient access control, which allows remote attackers to obtain user credentials.

    Published: 1 Nov 2005