CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2005-3068

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Eric Integrated Development Environment (eric3) before 3.7.2 has unknown impact and attack vectors related to a "potential security exploit."

    Published: 27 Sept 2005
    7.5
    High

    CVE-2005-3074

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in rsyslogd in RSyslog before 1.0.1 and before 1.10.1 allows remote attackers to execute arbitrary SQL commands via crafted syslog messages.

    Published: 27 Sept 2005
    7.5
    High

    CVE-2005-3075

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Zengaia before 0.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

    Published: 27 Sept 2005
    2.1
    Low

    CVE-2005-3071

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Unix File System (UFS) on Solaris 8 and 9, when logging is enabled, allows local users to cause a denial of service ("soft hang") via certain write operations to UFS.

    Published: 27 Sept 2005
    5
    Medium

    CVE-2005-3080

    Last Modified: 16 Apr 2026

    contrib/example.php in GeSHi before 1.0.7.3 allows remote attackers to read arbitrary files via the language field without a source field set.

    Published: 27 Sept 2005
    4.6
    Medium

    CVE-2005-3081

    Last Modified: 16 Apr 2026

    wzdftpd 0.5.4 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the SITE command.

    Published: 27 Sept 2005
    7.5
    High

    CVE-2005-3082

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in admin.php in SEO-Board 1.0.2 allows remote attackers to execute arbitrary SQL commands via the user_pass_sha1 value in a cookie.

    Published: 27 Sept 2005
    4.3
    Medium

    CVE-2005-3083

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 0.10 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 27 Sept 2005
    5
    Medium

    CVE-2005-3084

    Last Modified: 16 Apr 2026

    Buffer overflow in the TIFF library in the Photo Viewer for Sony PSP 2.0 firmware allows remote attackers to cause a denial of service via a crafted TIFF image.

    Published: 27 Sept 2005
    4.3
    Medium

    CVE-2005-3078

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in PunBB before 1.2.8 allows remote attackers to inject arbitrary web script or HTML via the "forgotten e-mail" feature.

    Published: 27 Sept 2005
    7.5
    High

    CVE-2005-3061

    Last Modified: 16 Apr 2026

    Multiple stack-based buffer overflows in PowerArchiver 8.10 through 9.5 Beta 4 and Beta 5 allow remote attackers to execute arbitrary code via a long filename in a (1) ACE or (2) ARJ archive.

    Published: 27 Sept 2005
    7.5
    High

    CVE-2005-3062

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in AlstraSoft E-Friends 4.0 allows remote attackers to execute arbitrary PHP code via the mode parameter.

    Published: 27 Sept 2005
    7.5
    High

    CVE-2005-3063

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in MailGust 1.9 allows remote attackers to execute arbitrary SQL commands via the email field on the password reminder page.

    Published: 27 Sept 2005
    4.3
    Medium

    CVE-2005-3066

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in perldiver.pl in PerlDiver 1.x allows remote attackers to inject arbitrary web script or HTML via the query string. NOTE: this issue was originally disputed by the vendor, but it has since been acknowledged.

    Published: 27 Sept 2005
    5
    Medium

    CVE-2005-3073

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Interchange 5.0.1 allows attackers 4.9.3, 5.0 before 5.0.2, and 5.2, when a catalog has been created using the (1) "mike", (2) "standard", or (3) "foundation" demo, allows attackers to inject Interchange Tag Language (ITL) elements into the forum/submit.html page.

    Published: 27 Sept 2005
    7.5
    High

    CVE-2005-3076

    Last Modified: 16 Apr 2026

    Simplog 0.9.1 might allow remote attackers to execute arbitrary SQL commands or trigger SQL error messages via invalid (1) pid, (2) blogid, (3) cid, or (4) m parameters to archive.php, or the (5) blogid parameter to blogadmin.php.

    Published: 27 Sept 2005
    4.6
    Medium

    CVE-2005-3079

    Last Modified: 16 Apr 2026

    PunBB before 1.2.8 allows remote attackers to perform "code inclusion" via the user language selection.

    Published: 27 Sept 2005
    4.3
    Medium

    CVE-2005-3085

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in rss.php in Riverdark Studios RSS Syndicator module 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) forum or (2) topic parameters.

    Published: 27 Sept 2005
    5
    Medium

    CVE-2005-3087

    Last Modified: 16 Apr 2026

    The SecureW2 3.0 TLS implementation uses weak random number generators (rand and srand from system time) during generation of the pre-master secret (PMS), which makes it easier for attackers to guess the secret and decrypt sensitive data.

    Published: 27 Sept 2005
    2.1
    Low

    CVE-2005-3069

    Last Modified: 16 Apr 2026

    xferfaxstats in HylaFax 4.2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on the xferfax$$ temporary file.

    Published: 27 Sept 2005
    3.6
    Low

    CVE-2005-3070

    Last Modified: 16 Apr 2026

    HylaFax 4.2.1 and earlier does not create or verify ownership of the UNIX domain socket, which might allow local users to read faxes and cause a denial of service by creating the socket using the hyla.unix temporary file.

    Published: 27 Sept 2005
    7.5
    High

    CVE-2005-3072

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in pages/forum/submit.html in Interchange 4.9.3 up to 5.2.0 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

    Published: 27 Sept 2005
    5
    Medium

    CVE-2005-3077

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 5.2.3 for Mac OS allows remote attackers to cause a denial of service (crash) via a web page with malformed attributes in a BGSOUND tag, possibly involving double-quotes in an about: URI.

    Published: 27 Sept 2005
    6.4
    Medium

    CVE-2005-3086

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in admin/about.php in contentServ 3.1 allows remote attackers to read or include arbitrary files via ".." sequences in the ctsWebsite parameter.

    Published: 27 Sept 2005
    10
    Critical

    CVE-2005-3059

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Opera 8.50 on Linux and Windows have unknown impact and attack vectors, related to (1) " handling of must-revalidate cache directive for HTTPS pages" or (2) a "display issue with cookie comment encoding."

    Published: 26 Sept 2005
    2.1
    Low

    CVE-2005-3054

    Last Modified: 16 Apr 2026

    fopen_wrappers.c in PHP 4.4.0, and possibly other versions, does not properly restrict access to other directories when the open_basedir directive includes a trailing slash, which allows PHP scripts in one directory to access files in other directories whose names are substrings of the original directory.

    Published: 26 Sept 2005
    5.1
    Medium

    CVE-2005-2710

    Last Modified: 16 Apr 2026

    Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via the (1) image handle or (2) timeformat attribute in a RealPix (.rp) or RealText (.rt) file.

    Published: 26 Sept 2005
    5
    Medium

    CVE-2010-1204

    Last Modified: 11 Apr 2025

    Search.pm in Bugzilla 2.17.1 through 3.2.6, 3.3.1 through 3.4.6, 3.5.1 through 3.6, and 3.7 allows remote attackers to obtain potentially sensitive time-tracking information via a crafted search URL, related to a "boolean chart search."

    Published: 25 Sept 2005
    2.1
    Low

    CVE-2005-3055

    Last Modified: 16 Apr 2026

    Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause a denial of service (kernel OOPS) via a userspace process that issues a USB Request Block (URB) to a USB device and terminates before the URB is finished, which leads to a stale pointer reference.

    Published: 25 Sept 2005
    5
    Medium

    CVE-2005-4798

    Last Modified: 16 Apr 2026

    Buffer overflow in NFS readlink handling in the Linux Kernel 2.4 up to 2.4.31 allows remote NFS servers to cause a denial of service (crash) via a long symlink, which is not properly handled in (1) nfs2xdr.c or (2) nfs3xdr.c and causes a crash in the NFS client.

    Published: 25 Sept 2005
    6.8
    Medium

    CVE-2005-3046

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in password.php in PhpMyFaq 1.5.1 allows remote attackers to modify SQL queries and gain administrator privileges via the user field.

    Published: 23 Sept 2005
    4.3
    Medium

    CVE-2005-3047

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFaq 1.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PMF_CONF[version] parameter to footer.php or (2) PMF_LANG[metaLanguage] to header.php.

    Published: 23 Sept 2005
    5
    Medium

    CVE-2005-3049

    Last Modified: 16 Apr 2026

    PhpMyFaq 1.5.1 stores data files under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain sensitive information via a direct request to the data/tracking[DATE] file.

    Published: 23 Sept 2005
    5
    Medium

    CVE-2005-3050

    Last Modified: 16 Apr 2026

    PhpMyFaq 1.5.1 allows remote attackers to obtain sensitive information via a LANGCODE parameter that does not exist, which reveals the path in an error message.

    Published: 23 Sept 2005
    9.3
    Critical

    CVE-2005-3051

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the ARJ plugin (arj.dll) 3.9.2.0 for 7-Zip 3.13, 4.23, and 4.26 BETA, as used in products including Turbo Searcher, allows remote attackers to execute arbitrary code via a large ARJ block.

    Published: 23 Sept 2005
    7.5
    High

    CVE-2005-3045

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search.php in My Little Forum 1.5 and 1.6 beta allows remote attackers to execute arbitrary SQL commands via the phrase field.

    Published: 23 Sept 2005
    6.4
    Medium

    CVE-2005-3048

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in PhpMyFaq 1.5.1 allows remote attackers to read arbitrary files or include arbitrary PHP files via a .. (dot dot) in the LANGCODE parameter, which also allows direct code injection via the User Agent field in a request packet, which can be activated by using LANGCODE to reference the user tracking data file.

    Published: 23 Sept 2005
    7.5
    High

    CVE-2005-3052

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in module/down.inc.php in jportal 2.3.1 allows remote attackers to execute arbitrary SQL commands via the search field to download.php.

    Published: 23 Sept 2005
    7.5
    High

    CVE-2005-2337

    Last Modified: 16 Apr 2026

    Ruby 1.6.x up to 1.6.8, 1.8.x up to 1.8.2, and 1.9.0 development up to 2005-09-01 allows attackers to bypass safe level and taint flag protections and execute disallowed code when Ruby processes a program through standard input (stdin).

    Published: 23 Sept 2005
    7.5
    High

    CVE-2005-3031

    Last Modified: 16 Apr 2026

    Buffer overflow in vxFtpSrv 0.9.7 allows remote attackers to execute arbitrary code via a long USER name.

    Published: 22 Sept 2005
    7.5
    High

    CVE-2005-3032

    Last Modified: 16 Apr 2026

    Buffer overflow in vxTftpSrv 1.7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TFTP request with a long filename argument.

    Published: 22 Sept 2005
    7.5
    High

    CVE-2005-3033

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in vxWeb 1.1.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.

    Published: 22 Sept 2005
    7.5
    High

    CVE-2005-3034

    Last Modified: 16 Apr 2026

    Compuware DriverStudio Remote Control service (DSRsvc.exe) 2.7 and 3.0 beta 2 allows remote attackers to bypass authentication via a null session.

    Published: 22 Sept 2005
    5
    Medium

    CVE-2005-3038

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Hosting Controller 6.1 before Hotfix 2.4 allows remote attackers to list and read contents of arbitrary drives, related to "the PHP vulnerability."

    Published: 22 Sept 2005
    7.5
    High

    CVE-2005-3039

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in infopage.asp in Mall23 eCommerce allows remote attackers to execute arbitrary SQL commands via the idPage parameter.

    Published: 22 Sept 2005
    5
    Medium

    CVE-2005-3040

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the web interface (ISALogin.dll) for TAC Vista 4.0, and possibly other versions before 4.3, allows remote attackers to read arbitrary files via ".." sequences in the Template parameter.

    Published: 22 Sept 2005
    5
    Medium

    CVE-2005-3041

    Last Modified: 16 Apr 2026

    Unspecified "drag-and-drop vulnerability" in Opera Web Browser before 8.50 on Windows allows "unintentional file uploads."

    Published: 22 Sept 2005
    7.5
    High

    CVE-2005-3042

    Last Modified: 16 Apr 2026

    miniserv.pl in Webmin before 1.230 and Usermin before 1.160, when "full PAM conversations" is enabled, allows remote attackers to bypass authentication by spoofing session IDs via certain metacharacters (line feed or carriage return).

    Published: 22 Sept 2005
    7.5
    High

    CVE-2005-3043

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in AddItem.asp in Mall23 eCommerce allows remote attackers to execute arbitrary SQL commands via the idOption_Dropdown_2 parameter.

    Published: 22 Sept 2005
    4.6
    Medium

    CVE-2005-3036

    Last Modified: 16 Apr 2026

    File Transfer Anywhere 3.01 stores sensitive password information in plaintext in the PASS value in the "File Transfer Anywhere" registry key, which allows local users to gain privileges.

    Published: 22 Sept 2005