CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2005-3261

    Last Modified: 16 Apr 2026

    getversions.php in versatileBulletinBoard (vBB) 1.0.0 RC2 lists the versions of all installed scripts, which allows remote attackers to obtain sensitive information via a direct request.

    Published: 20 Oct 2005
    7.5
    High

    CVE-2005-3262

    Last Modified: 16 Apr 2026

    Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via format string specifiers in a UUE/XXE file, which are not properly handled when WinRAR displays diagnostic errors related to an invalid filename.

    Published: 20 Oct 2005
    7.5
    High

    CVE-2005-3263

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in UNACEV2.DLL for RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via an ACE archive containing a file with a long name.

    Published: 20 Oct 2005
    4.3
    Medium

    CVE-2005-3264

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in thread.php for Zeroblog 1.1f and 1.2a allows remote attackers to inject arbitrary web script or HTML via the threadID parameter.

    Published: 20 Oct 2005
    7.2
    High

    CVE-2005-3270

    Last Modified: 16 Apr 2026

    Untrusted search path vulnerability in DiskMountNotify for Symantec Norton AntiVirus 9.0.3 allows local users to gain privileges by modifying the PATH to reference a malicious (1) ps or (2) grep file.

    Published: 20 Oct 2005
    7.2
    High

    CVE-2005-2759

    Last Modified: 16 Apr 2026

    ** SPLIT ** The jlucaller program in LiveUpdate for Symantec Norton AntiVirus 9.0.3 on Macintosh runs setuid when executing Java programs, which allows local users to gain privileges. NOTE: due to a CNA error, this candidate was also originally assigned to an issue in DiskMountNotify. Use CVE-2005-3270 for the DiskMountNotify issue, and CVE-2005-2759 for the LiveUpdate issue.

    Published: 20 Oct 2005
    7.5
    High

    CVE-2005-2971

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the KWord RTF importer for KOffice 1.2.0 through 1.4.1 allows remote attackers to execute arbitrary code via a crafted RTF file.

    Published: 20 Oct 2005
    7.5
    High

    CVE-2005-3259

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in versatileBulletinBoard (vBB) 1.0.0 RC2 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) login field, (2) "search this thread" feature, (3) "search for posts" feature, (4) "forgot password" feature, (5) list parameter in userlistpre.php, and the (6) select, (7) categ, and (8) to parameters in index.php.

    Published: 20 Oct 2005
    4.3
    Medium

    CVE-2005-3260

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in versatileBulletinBoard (vBB) 1.0.0 RC2 allow remote attackers to inject arbitrary web script or HTML via (1) the url parameter in dereferrer.php and (2) the file parameter in imagewin.php.

    Published: 20 Oct 2005
    2.1
    Low

    CVE-2005-3268

    Last Modified: 16 Apr 2026

    yiff server (yiff-server) 2.14.2 on Debian GNU/Linux runs as root and does not properly verify ownership of files that it opens, which allows local users to read arbitrary files.

    Published: 20 Oct 2005
    7.5
    High

    CVE-2005-3269

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in help.cgi in the HTTP administrative interface for (1) Sun Java System Directory Server 5.2 2003Q4, 2004Q2, and 2005Q1, (2) Red Hat Directory Server and (3) Certificate Server before 7.1 SP1, (4) Sun ONE Directory Server 5.1 SP4 and earlier, and (5) Sun ONE Administration Server 5.2 allows remote attackers to cause a denial of service (admin server crash), or local users to gain root privileges.

    Published: 20 Oct 2005
    2.1
    Low

    CVE-2005-3271

    Last Modified: 16 Apr 2026

    Exec in Linux kernel 2.6 does not properly clear posix-timers in multi-threaded environments, which results in a resource leak and could allow a large number of multiple local users to cause a denial of service by using more posix-timers than specified by the quota for a single user.

    Published: 20 Oct 2005
    5
    Medium

    CVE-2005-3258

    Last Modified: 16 Apr 2026

    The rfc1738_do_escape function in ftp.c for Squid 2.5 STABLE11 and earlier allows remote FTP servers to cause a denial of service (segmentation fault) via certain "odd" responses.

    Published: 20 Oct 2005
    10
    Critical

    CVE-2005-3184

    Last Modified: 16 Apr 2026

    Buffer overflow vulnerability in the unicode_to_bytes in the Service Location Protocol (srvloc) dissector (packet-srvloc.c) in Ethereal allows remote attackers to execute arbitrary code via a srvloc packet with a modified length value.

    Published: 19 Oct 2005
    5
    Medium

    CVE-2005-3241

    Last Modified: 16 Apr 2026

    Multiple vulnerabilities in Ethereal 0.10.12 and earlier allow remote attackers to cause a denial of service (memory consumption) via unspecified vectors in the (1) ISAKMP, (2) FC-FCS, (3) RSVP, and (4) ISIS LSP dissector.

    Published: 19 Oct 2005
    5
    Medium

    CVE-2005-3246

    Last Modified: 16 Apr 2026

    Ethereal 0.10.12 and earlier allows remote attackers to cause a denial of service (null dereference) via unknown vectors in the (1) SCSI, (2) sFlow, or (3) RTnet dissectors.

    Published: 19 Oct 2005
    5
    Medium

    CVE-2005-3247

    Last Modified: 16 Apr 2026

    The SigComp UDVM in Ethereal 0.10.12 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.

    Published: 19 Oct 2005
    5
    Medium

    CVE-2005-3248

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the X11 dissector in Ethereal 0.10.12 and earlier allows remote attackers to cause a denial of service (divide-by-zero) via unknown vectors.

    Published: 19 Oct 2005
    6.4
    Medium

    CVE-2005-3249

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the WSP dissector in Ethereal 0.10.1 to 0.10.12 allows remote attackers to cause a denial of service or corrupt memory via unknown vectors that cause Ethereal to free an invalid pointer.

    Published: 19 Oct 2005
    7.5
    High

    CVE-2005-3243

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Ethereal 0.10.12 and earlier might allow remote attackers to execute arbitrary code via unknown vectors in the (1) SLIMP3 and (2) AgentX dissector.

    Published: 19 Oct 2005
    5
    Medium

    CVE-2005-3244

    Last Modified: 16 Apr 2026

    The BER dissector in Ethereal 0.10.3 to 0.10.12 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.

    Published: 19 Oct 2005
    5
    Medium

    CVE-2005-3245

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the ONC RPC dissector in Ethereal 0.10.3 to 0.10.12, when the "Dissect unknown RPC program numbers" option is enabled, allows remote attackers to cause a denial of service (memory consumption).

    Published: 19 Oct 2005
    5
    Medium

    CVE-2005-3242

    Last Modified: 16 Apr 2026

    Ethereal 0.10.12 and earlier allows remote attackers to cause a denial of service (crash) via unknown vectors in (1) the IrDA dissector and (2) the SMB dissector when SMB transaction payload reassembly is enabled.

    Published: 19 Oct 2005
    10
    Critical

    CVE-2005-3254

    Last Modified: 16 Apr 2026

    The CGIwrap program before 3.9 on Debian GNU/Linux uses an incorrect minimum value of 100 for a UID to determine whether it can perform a seteuid operation, which could allow attackers to execute code as other system UIDs that are greater than the minimum value, which should be 1000 on Debian systems.

    Published: 18 Oct 2005
    5
    Medium

    CVE-2005-3255

    Last Modified: 16 Apr 2026

    The (1) cgiwrap and (2) php-cgiwrap packages before 3.9 in Debian GNU/Linux provide access to debugging CGIs under the web document root, which allows remote attackers to obtain sensitive information via direct requests to those CGIs.

    Published: 18 Oct 2005
    5
    Medium

    CVE-2005-3256

    Last Modified: 16 Apr 2026

    The key selection dialogue in Enigmail before 0.92.1 can incorrectly select a key with a user ID that does not have additional information, which allows parties with that key to decrypt the message.

    Published: 18 Oct 2005
    7.5
    High

    CVE-2005-3252

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to execute arbitrary code via a crafted UDP packet.

    Published: 18 Oct 2005
    7.5
    High

    CVE-2005-2978

    Last Modified: 16 Apr 2026

    pnmtopng in netpbm before 10.25, when using the -trans option, uses uninitialized size and index variables when converting Portable Anymap (PNM) images to Portable Network Graphics (PNG), which might allow attackers to execute arbitrary code by modifying the stack.

    Published: 18 Oct 2005
    6.4
    Medium

    CVE-2005-3251

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the gallery script in Gallery 2.0 (G2) allows remote attackers to read or include arbitrary files via ".." sequences in the g2_itemId parameter.

    Published: 17 Oct 2005
    2.1
    Low

    CVE-2005-3250

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Solaris 10 allows local users to cause a denial of service (panic) via unknown vectors related to the "/proc" filesystem, which trigger a null dereference.

    Published: 17 Oct 2005
    9.8
    Critical

    CVE-2005-3120

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.

    Published: 17 Oct 2005
    4.6
    Medium

    CVE-2005-3257

    Last Modified: 16 Apr 2026

    The VT implementation (vt_ioctl.c) in Linux kernel 2.6.12, and possibly other versions including 2.6.14.4, allows local users to use the KDSKBSENT ioctl on terminals of other users and gain privileges, as demonstrated by modifying key bindings using loadkeys.

    Published: 15 Oct 2005
    7.5
    High

    CVE-2005-2661

    Last Modified: 16 Apr 2026

    Format string vulnerability in the ParseBannerAndCapability function in main.c for up-imapproxy 1.2.3 and 1.2.4 allows remote IMAP servers to execute arbitrary code via format string specifiers in a banner or capability line.

    Published: 14 Oct 2005
    Unknown

    CVE-2005-3195

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-3178. Reason: this candidate is a duplicate of CVE-2005-3178; the duplicate arose from a pre-candidate that was not deleted during the editing phase. Notes: All CVE users should reference CVE-2005-3178 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 14 Oct 2005
    7.5
    High

    CVE-2005-3199

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in aradmin.asp for aspReady FAQ allow remote attackers to execute arbitrary SQL commands, possibly via the (1) txtLogin and (2) txtPassword parameters.

    Published: 14 Oct 2005
    4.3
    Medium

    CVE-2005-3200

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Utopia News Pro (UNP) 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the sitetitle parameter in header.php and (2) the version and (3) query_count parameters in footer.php.

    Published: 14 Oct 2005
    7.5
    High

    CVE-2005-3201

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in news.php for Utopia News Pro (UNP) 1.1.3, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary SQL via the newsid parameter.

    Published: 14 Oct 2005
    6.8
    Medium

    CVE-2005-3202

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTML DB (HTMLDB) 1.3 through 1.3.6 allow remote attackers to inject arbitrary web script or HTML, and subsequently execute SQL statements via the (1) p or (2) p_t02 parameters.

    Published: 14 Oct 2005
    4.6
    Medium

    CVE-2005-3203

    Last Modified: 16 Apr 2026

    The manual installation of Oracle HTML DB (HTMLDB) 1.3 through 1.3.6 stores the SYS password in install.lst in plaintext, which allows local users to gain privileges.

    Published: 14 Oct 2005
    4.3
    Medium

    CVE-2005-3204

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Oracle XML DB 9iR2 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP request.

    Published: 14 Oct 2005
    4.6
    Medium

    CVE-2005-3198

    Last Modified: 16 Apr 2026

    Webroot Desktop Firewall before 1.3.0build52 allows local users to disable the firewall, even when password protection is enabled, via certain DeviceIoControl commands.

    Published: 14 Oct 2005
    6.8
    Medium

    CVE-2005-3208

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in (1) aeNovo, (2) aeNovoShop and (3) aeNovoWYSI allow remote attackers to execute arbitrary SQL code via (a) the password parameter in control.asp, and (b) the strSQL parameter in search.asp, which can enable XSS attacks in resulting error messages.

    Published: 14 Oct 2005
    4.6
    Medium

    CVE-2005-3209

    Last Modified: 16 Apr 2026

    Aenovo products (1) aeNovo, (2) aeNovoShop, and (3) aeNovoWYSI store password information in plaintext in the (a) control, (b) content, and (c) page tables, which allows attackers with database access to obtain those passwords and gain privileges.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3211

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of BitDefender Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3212

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of NOD32 Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3218

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of Dr.Web Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3219

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of Avira Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3223

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of Rising Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3224

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of AntiVir Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3225

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of (1) eTrust-Iris and (2) eTrust-Vet Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005