CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2005-2961

    Last Modified: 16 Apr 2026

    Buffer overflow in the get_string_ahref function for ProZilla 1.3.7.4 and possibly earlier, with the -ftpsearch option enabled, allows remote servers to execute arbitrary code via a search response with a crafted string in the HREF field of an <A> tag.

    Published: 5 Oct 2005
    5
    Medium

    CVE-2005-3139

    Last Modified: 16 Apr 2026

    Bugzilla 2.19.1 through 2.20rc2 and 2.21, with user matching turned on in substring mode, allows attackers to list all users whose names match an arbitrary substring, even when the usevisibilitygroups parameter is set.

    Published: 5 Oct 2005
    7.5
    High

    CVE-2005-3155

    Last Modified: 16 Apr 2026

    Buffer overflow in the W3C logging for MailEnable Enterprise 1.1 and Professional 1.6 allows remote attackers to execute arbitrary code.

    Published: 5 Oct 2005
    2.1
    Low

    CVE-2005-2100

    Last Modified: 16 Apr 2026

    The rw_vm function in usercopy.c in the 4GB split patch for the Linux kernel in Red Hat Enterprise Linux 4 does not perform proper bounds checking, which allows local users to cause a denial of service (crash).

    Published: 5 Oct 2005
    5.1
    Medium

    CVE-2005-3178

    Last Modified: 16 Apr 2026

    Buffer overflow in xloadimage 4.1 and earlier, and xli, might allow user-assisted attackers to execute arbitrary code via a long title name in a NIFF file, which triggers the overflow during (1) zoom, (2) reduce, or (3) rotate operations.

    Published: 5 Oct 2005
    5
    Medium

    CVE-2005-2804

    Last Modified: 16 Apr 2026

    Integer overflow in the registry parsing code in GroupWise 6.5.3, and possibly earlier version, allows remote attackers to cause a denial of service (application crash) via a large TCP/IP port in the Windows registry key.

    Published: 4 Oct 2005
    4.3
    Medium

    CVE-2005-3127

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in lucidCMS 1.0.11 allows remote attackers to inject arbitrary web script or HTML via the query string.

    Published: 4 Oct 2005
    4.3
    Medium

    CVE-2005-3128

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in add.php in Address Add Plugin 1.9 and 2.0 for Squirrelmail allows remote attackers to inject arbitrary web script or HTML via the IMG tag.

    Published: 4 Oct 2005
    5.1
    Medium

    CVE-2005-3129

    Last Modified: 16 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in Serendipity 0.8.4 and earlier allows remote attackers to perform unauthorized actions as a logged in user via a link or IMG tag to serendipity_admin.php.

    Published: 4 Oct 2005
    7.5
    High

    CVE-2005-3130

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in lucidCMS 1.0.11 allows remote attackers to execute arbitrary SQL commands via the login field.

    Published: 4 Oct 2005
    7.5
    High

    CVE-2005-3134

    Last Modified: 16 Apr 2026

    Citrix Metaframe Presentation Server 3.0 and 4.0 allows remote attackers to bypass policy restrictions by downloading the launch.ica file and changing the client device name (ClientName).

    Published: 4 Oct 2005
    7.5
    High

    CVE-2005-3135

    Last Modified: 16 Apr 2026

    Buffer overflow in Virtools Web Player 3.0.0.100 and earlier allows remote attackers to execute arbitrary code via a long filename.

    Published: 4 Oct 2005
    5
    Medium

    CVE-2005-3132

    Last Modified: 16 Apr 2026

    MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to bwlist_inc.html, which reveals the path in an error message.

    Published: 4 Oct 2005
    5
    Medium

    CVE-2005-3136

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Virtools Web Player 3.0.0.100 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a filename.

    Published: 4 Oct 2005
    4.3
    Medium

    CVE-2005-3131

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to blank.html, or the createdataCX parameter to (2) calendar_d.html, (3) calendar_m.html, or (4) calendar_w.html.

    Published: 4 Oct 2005
    5
    Medium

    CVE-2005-3133

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to (1) delete arbitrary files or directories via a relative path to the id parameter to logout.html or (2) include arbitrary PHP files or other files via the helpid parameter to help.html.

    Published: 4 Oct 2005
    5
    Medium

    CVE-2005-3180

    Last Modified: 16 Apr 2026

    The Orinoco driver (orinoco.c) in Linux kernel 2.6.13 and earlier does not properly clear memory from a previously used packet whose length is increased, which allows remote attackers to obtain sensitive information.

    Published: 4 Oct 2005
    7.5
    High

    CVE-2005-2933

    Last Modified: 16 Apr 2026

    Buffer overflow in the mail_valid_net_parse_work function in mail.c for Washington's IMAP Server (UW-IMAP) before imap-2004g allows remote attackers to execute arbitrary code via a mailbox name containing a single double-quote (") character without a closing quote, which causes bytes after the double-quote to be copied into a buffer indefinitely.

    Published: 4 Oct 2005
    2.1
    Low

    CVE-2005-2973

    Last Modified: 16 Apr 2026

    The udp_v6_get_port function in udp.c in Linux 2.6 before 2.6.14-rc5, when running IPv6, allows local users to cause a denial of service (infinite loop and crash).

    Published: 4 Oct 2005
    5
    Medium

    CVE-2005-3353

    Last Modified: 16 Apr 2026

    The exif_read_data function in the Exif module in PHP before 4.4.1 allows remote attackers to cause a denial of service (infinite loop) via a malformed JPEG image.

    Published: 2 Oct 2005
    2.1
    Low

    CVE-2005-2660

    Last Modified: 16 Apr 2026

    apachetop 0.12.5 and earlier, when running in debug mode, allows local users to create or append to arbitrary files via a symlink attack on atop.debug.

    Published: 30 Sept 2005
    2.1
    Low

    CVE-2005-3111

    Last Modified: 16 Apr 2026

    The handler code for backupninja 0.8 and earlier creates temporary files with predictable filenames, which allows local users to modify arbitrary files via a symlink attack.

    Published: 30 Sept 2005
    7.5
    High

    CVE-2005-3113

    Last Modified: 16 Apr 2026

    The ActiveX control for NateOn Messenger (NateonDownloadManager.ocx) allows remote attackers to download and execute arbitrary programs by setting the arguments to the GotNate.Excute method.

    Published: 30 Sept 2005
    2.1
    Low

    CVE-2005-2962

    Last Modified: 16 Apr 2026

    The post-installation script for ntlmaps before 0.9.9 sets world-readable permissions for the configuration file, which allows local users to obtain the username and password.

    Published: 30 Sept 2005
    7.2
    High

    CVE-2005-3060

    Last Modified: 16 Apr 2026

    Buffer overflow in getconf in IBM AIX 5.2 to 5.3 allows local users to execute arbitrary code via unknown vectors.

    Published: 30 Sept 2005
    2.1
    Low

    CVE-2005-3112

    Last Modified: 16 Apr 2026

    The "reset password" feature in Macromedia Breeze 5.0 stores passwords in plaintext in the database instead of the hash, which allows attackers with access to the database to obtain the passwords.

    Published: 30 Sept 2005
    7.5
    High

    CVE-2005-3114

    Last Modified: 16 Apr 2026

    Buffer overflow in the ActiveX control for NateOn Messenger (NateonDownloadManager.ocx) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long third argument to the GotNate.Excute method.

    Published: 30 Sept 2005
    2.1
    Low

    CVE-2005-3115

    Last Modified: 16 Apr 2026

    mpeg-tools before 1.5b-r2 creates multiple temporary files insecurely, which allows local users to overwrite arbitrary files via (1) ts.stat, (2) ts.mpg, (3) foobar, (4) blockbar, or (5) foobar[NNN].

    Published: 30 Sept 2005
    4.3
    Medium

    CVE-2005-2557

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the dir parameter, as identified by bug#0005959, and a different vulnerability than CVE-2005-3090.

    Published: 28 Sept 2005
    7.5
    High

    CVE-2005-2964

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in AbiWord before 2.2.10 allows attackers to execute arbitrary code via the RTF import mechanism.

    Published: 28 Sept 2005
    4.3
    Medium

    CVE-2005-3090

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in bug_actiongroup_page.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the summary of the bug, which is not quoted when view_all_bug_page.php is used to delete the bug, as identified by bug#0006002, a different vulnerability than CVE-2005-2557.

    Published: 28 Sept 2005
    4.3
    Medium

    CVE-2005-3091

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Mantis before 1.0.0rc1 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, as identified by bug#0005751 "thraxisp".

    Published: 28 Sept 2005
    5
    Medium

    CVE-2005-3093

    Last Modified: 16 Apr 2026

    Nokia 7610 and 3210 phones allows attackers to cause a denial of service via certain characters in the filename of a Bluetooth OBEX transfer.

    Published: 28 Sept 2005
    5
    Medium

    CVE-2005-3097

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Avi Alkalay contribute.cgi (aka contribute.pl), dated 16 Jun 2002, allows remote attackers to overwrite arbitrary files via ".." sequences in the contribdir variable.

    Published: 28 Sept 2005
    4.6
    Medium

    CVE-2005-3098

    Last Modified: 16 Apr 2026

    poppassd in Qualcomm qpopper 4.0.8 allows local users to modify arbitrary files and gain privileges via the -t (trace file) command line argument.

    Published: 28 Sept 2005
    4.6
    Medium

    CVE-2005-3099

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the (1) Xsun and (2) Xprt commands in Solaris 7, 8, 9, and 10 allows local users to execute arbitrary code.

    Published: 28 Sept 2005
    5
    Medium

    CVE-2005-3100

    Last Modified: 16 Apr 2026

    Unspecified "PPTP Remote DoS Vulnerability" in Astaro Security Linux 4.027 allows attackers to cause a denial of service.

    Published: 28 Sept 2005
    7.5
    High

    CVE-2005-3092

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Image-Line Software FL Studio 5.0.1 allows remote attackers to execute arbitrary code via a .flp file that contains a long path to a (1) .mid or (2) .wav file.

    Published: 28 Sept 2005
    7.5
    High

    CVE-2005-3095

    Last Modified: 16 Apr 2026

    Avi Alkalay notify program, dated 19 Aug 2001, allows remote attackers to execute arbitrary commands via shell metacharacters in the from parameter.

    Published: 28 Sept 2005
    7.5
    High

    CVE-2005-3096

    Last Modified: 16 Apr 2026

    Avi Alkalay nslookup.cgi program, dated 16 June 2002, allows remote attackers to execute arbitrary commands via shell metacharacters in the query parameter.

    Published: 28 Sept 2005
    5
    Medium

    CVE-2005-3101

    Last Modified: 16 Apr 2026

    The password reset feature in Movable Type before 3.2 generates different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames.

    Published: 28 Sept 2005
    5
    Medium

    CVE-2005-3102

    Last Modified: 16 Apr 2026

    The administrative interface in Movable Type allows attackers to upload files with arbitrary extensions under the web root.

    Published: 28 Sept 2005
    4.3
    Medium

    CVE-2005-3103

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Movable Type before 3.2 allows remote attackers to inject arbitrary web script or HTML via the (1) title, (2) category, (3) body, (4) extended body, and (5) excerpt form fields in new blog entries.

    Published: 28 Sept 2005
    2.6
    Low

    CVE-2005-3104

    Last Modified: 16 Apr 2026

    mt-comments.cgi in Movable Type before 3.2 allows attackers to redirect users to other web sites via URLs in comments.

    Published: 28 Sept 2005
    7.5
    High

    CVE-2005-3094

    Last Modified: 16 Apr 2026

    Avi Alkalay man-cgi script allows remote attackers to execute arbitrary code via shell metacharacters in the topic parameter.

    Published: 28 Sept 2005
    4.6
    Medium

    CVE-2006-0225

    Last Modified: 16 Apr 2026

    scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell metacharacters or spaces, which are expanded twice.

    Published: 28 Sept 2005
    7.5
    High

    CVE-2006-1856

    Last Modified: 16 Apr 2026

    Certain modifications to the Linux kernel 2.6.16 and earlier do not add the appropriate Linux Security Modules (LSM) file_permission hooks to the (1) readv and (2) writev functions, which might allow attackers to bypass intended access restrictions.

    Published: 28 Sept 2005
    5
    Medium

    CVE-2005-3064

    Last Modified: 16 Apr 2026

    MultiTheftAuto 0.5 patch 1 and earlier does not properly verify client privileges when running command 40, which allows remote attackers to change or delete the message of the day (motd.txt).

    Published: 27 Sept 2005
    5
    Medium

    CVE-2005-3065

    Last Modified: 16 Apr 2026

    MultiTheftAuto 0.5 patch 1 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted command 40 that causes a -1 length to be used and triggers an out-of-bounds read.

    Published: 27 Sept 2005
    4.3
    Medium

    CVE-2005-3067

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in perldiver.cgi in PerlDiver 2.x allows remote attackers to inject arbitrary web script or HTML via the module parameter.

    Published: 27 Sept 2005