CVE Feed

    Dashboard / CVE

    5.1
    Medium

    CVE-2005-3226

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of ArcaVir Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3230

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of Panda Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3231

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of CAT Quick Heal allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3232

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of TheHacker allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3233

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of Trustix Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005
    4.3
    Medium

    CVE-2005-3237

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Cyphor 0.19 allows remote attackers to inject arbitrary web script or HTML via the t_login parameter of footer.php.

    Published: 14 Oct 2005
    2.1
    Low

    CVE-2005-3238

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Solaris 10 SCTP Socket Option Processing allows local users to cause a denial of service (panic) via unspecified attack vectors.

    Published: 14 Oct 2005
    5
    Medium

    CVE-2005-3206

    Last Modified: 16 Apr 2026

    iSQL*Plus (isqlplus) for Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to cause a denial of service (TNS listener stop) via an HTTP request with an sid parameter that contains a STOP command.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3221

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of Fortinet Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005
    7.8
    High

    CVE-2005-3239

    Last Modified: 16 Apr 2026

    The OLE2 unpacker in clamd in Clam AntiVirus (ClamAV) 0.87-1 allows remote attackers to cause a denial of service (segmentation fault) via a DOC file with an invalid property tree, which triggers an infinite recursion in the ole2_walk_property_tree function.

    Published: 14 Oct 2005
    7.5
    High

    CVE-2005-2967

    Last Modified: 16 Apr 2026

    Format string vulnerability in input_cdda.c in xine-lib 1-beta through 1-beta 3, 1-rc, 1.0 through 1.0.2, and 1.1.1 allows remote servers to execute arbitrary code via format string specifiers in metadata in CDDB server responses when the victim plays a CD.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3194

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in ALZip 6.12 (Korean), 6.1 (International), and 5.52 (English) allow remote attackers to execute arbitrary code via a long filename in a compressed (1) ALZ, (2) ARJ, (3) ZIP, (4) UUE, or (5) XXE archive.

    Published: 14 Oct 2005
    5
    Medium

    CVE-2005-3207

    Last Modified: 16 Apr 2026

    The forms servlet (f90servlet) in Oracle Forms 4.5.10.22 allows remote attackers to cause a denial of service (TNS listener stop) via a userid parameter that contains a STOP command.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3210

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of Kaspersky Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3214

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of Avast Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3215

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of McAfee Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3216

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of Sophos Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3217

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of Symantec Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3222

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of VBA32 Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3228

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of Ikarus AntiVirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3229

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of ClamAV Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3235

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of Proland Protector Plus 2000 Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005
    6.8
    Medium

    CVE-2005-3236

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Cyphor 0.19 allow remote attackers to execute arbitrary SQL and obtain administrative access via (1) the fid parameter of newmsg.php, which can enable XSS attacks when the SQL syntax is invalid or (2) the nick parameter of lostpwd.php.

    Published: 14 Oct 2005
    4.6
    Medium

    CVE-2005-3196

    Last Modified: 16 Apr 2026

    Planet Technology Corp FGSW2402RS switch with firmware 1.2 has a default password, which allows attackers with physical access to the device's serial port to gain privileges.

    Published: 14 Oct 2005
    7.2
    High

    CVE-2005-3197

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in PWIWrapper.dll for Webroot Desktop Firewall before 1.3.0build52 allows local users to execute arbitrary code as SYSTEM by sending a crafted DeviceIoControl command, then removing an allowed program from the firewall list.

    Published: 14 Oct 2005
    3.5
    Low

    CVE-2005-3205

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in iSQL*Plus (iSQLPlus) in Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to inject arbitrary web script or HTML via script in the "set markup HTML TABLE" command, which is executed when the user selects a table.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3213

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of F-Prot Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3220

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of Norman Virus Control Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3227

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of UNA Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005
    5.1
    Medium

    CVE-2005-3234

    Last Modified: 16 Apr 2026

    Multiple interpretation error in unspecified versions of Grisoft AVG Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

    Published: 14 Oct 2005
    7.5
    High

    CVE-2005-1985

    Last Modified: 16 Apr 2026

    The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.

    Published: 13 Oct 2005
    7.5
    High

    CVE-2005-2943

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in sendmail in XMail before 1.22 allows remote attackers to execute arbitrary code via a long -t command line option.

    Published: 13 Oct 2005
    2.1
    Low

    CVE-2005-2992

    Last Modified: 16 Apr 2026

    arc 5.21j and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different type of vulnerability than CVE-2005-2945.

    Published: 13 Oct 2005
    7.5
    High

    CVE-2005-3190

    Last Modified: 16 Apr 2026

    Buffer overflow in Computer Associates (CA) iGateway 3.0 and 4.0 before 4.0.050623, when running in debug mode, allows remote attackers to execute arbitrary code via HTTP GET requests.

    Published: 13 Oct 2005
    7.5
    High

    CVE-2005-1987

    Last Modified: 16 Apr 2026

    Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.

    Published: 13 Oct 2005
    6.5
    Medium

    CVE-2005-2120

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.

    Published: 13 Oct 2005
    7.5
    High

    CVE-2005-2963

    Last Modified: 16 Apr 2026

    The mod_auth_shadow module 1.0 through 1.5 and 2.0 for Apache with AuthShadow enabled uses shadow authentication for all locations that use the require group directive, even when other authentication mechanisms are specified, which might allow remote authenticated users to bypass security restrictions.

    Published: 13 Oct 2005
    10
    Critical

    CVE-2005-2715

    Last Modified: 16 Apr 2026

    Format string vulnerability in the Java user interface service (bpjava-msvc) daemon for VERITAS NetBackup Data and Business Center 4.5FP and 4.5MP, and NetBackup Enterprise/Server/Client 5.0, 5.1, and 6.0, allows remote attackers to execute arbitrary code via the COMMAND_LOGON_TO_MSERVER command.

    Published: 12 Oct 2005
    Unknown

    CVE-2005-2942

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate has been revoked by its Candidate Numbering Authority (CNA) because it was initially assigned to a problem that was not a security issue. Notes: none

    Published: 12 Oct 2005
    7.5
    High

    CVE-2005-3185

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and other products that use libcurl, when NTLM authentication is enabled, allows remote servers to execute arbitrary code via a long NTLM username.

    Published: 12 Oct 2005
    7.5
    High

    CVE-2005-1978

    Last Modified: 16 Apr 2026

    COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.

    Published: 11 Oct 2005
    5
    Medium

    CVE-2005-1979

    Last Modified: 16 Apr 2026

    Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the Transaction Internet Protocol (TIP) functionality.

    Published: 11 Oct 2005
    5
    Medium

    CVE-2005-2119

    Last Modified: 16 Apr 2026

    The MIDL_user_allocate function in the Microsoft Distributed Transaction Coordinator (MSDTC) proxy (MSDTCPRX.DLL) allocates a 4K page of memory regardless of the required size, which allows attackers to overwrite arbitrary memory locations using an incorrect size value that is provided to the NdrAllocate function, which writes management data to memory outside of the allocated buffer.

    Published: 11 Oct 2005
    5
    Medium

    CVE-2005-2128

    Last Modified: 16 Apr 2026

    QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value.

    Published: 11 Oct 2005
    7.2
    High

    CVE-2005-2925

    Last Modified: 16 Apr 2026

    runpriv in SGI IRIX allows local users to bypass intended restrictions and execute arbitrary commands via shell metacharacters in a command line for a privileged binary in /usr/sysadm/privbin.

    Published: 11 Oct 2005
    Unknown

    CVE-2005-2937

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-3663, CVE-2005-3664. Reason: this candidate was intended for one issue, but multiple advisories used this candidate for different issues. Notes: All CVE users should consult CVE-2005-3663 and CVE-2005-3664 to determine which ID is appropriate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 11 Oct 2005
    Unknown

    CVE-2005-2965

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-4802, CVE-2005-4803. Reason: this candidate was intended for one issue, but the description and references inadvertently combined multiple issues. Notes: All CVE users should consult CVE-2005-4802 and CVE-2005-4803 to determine which ID is appropriate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 11 Oct 2005
    5
    Medium

    CVE-2005-1980

    Last Modified: 16 Apr 2026

    Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after an error occurs, aka the "Distributed TIP Vulnerability."

    Published: 11 Oct 2005
    2.1
    Low

    CVE-2005-3179

    Last Modified: 16 Apr 2026

    drm.c in Linux kernel 2.6.10 to 2.6.13 creates a debug file in sysfs with world-readable and world-writable permissions, which allows local users to enable DRM debugging and obtain sensitive information.

    Published: 11 Oct 2005
    5
    Medium

    CVE-2005-2969

    Last Modified: 16 Apr 2026

    The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.

    Published: 11 Oct 2005