CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2005-3037

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Handy Address Book Server 1.1 allows remote attackers to inject arbitrary web script or HTML via the SEARCHTEXT parameter in a demos URL.

    Published: 22 Sept 2005
    5
    Medium

    CVE-2005-3035

    Last Modified: 16 Apr 2026

    Compuware DriverStudio Remote Control service (DSRsvc.exe) 2.7 and 3.0 beta 2 allows remote attackers to cause a denial of service (reboot) via a UDP packet sent directly to port 9110.

    Published: 22 Sept 2005
    5
    Medium

    CVE-2005-2703

    Last Modified: 16 Apr 2026

    Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies, including HTTP request smuggling and HTTP request splitting.

    Published: 22 Sept 2005
    5
    Medium

    CVE-2005-2704

    Last Modified: 16 Apr 2026

    Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spoof DOM objects via an XBL control that implements an internal XPCOM interface.

    Published: 22 Sept 2005
    7.5
    High

    CVE-2005-2705

    Last Modified: 16 Apr 2026

    Integer overflow in the JavaScript engine in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 might allow remote attackers to execute arbitrary code.

    Published: 22 Sept 2005
    6.4
    Medium

    CVE-2005-2706

    Last Modified: 16 Apr 2026

    Firefox before 1.0.7 and Mozilla before Suite 1.7.12 allows remote attackers to execute Javascript with chrome privileges via an about: page such as about:mozilla.

    Published: 22 Sept 2005
    5
    Medium

    CVE-2005-2707

    Last Modified: 16 Apr 2026

    Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spawn windows without user interface components such as the address and status bar, which could be used to conduct spoofing or phishing attacks.

    Published: 22 Sept 2005
    7.5
    High

    CVE-2005-2702

    Last Modified: 16 Apr 2026

    Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Unicode sequences with "zero-width non-joiner" characters.

    Published: 22 Sept 2005
    3.7
    Low

    CVE-2006-1542

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Python 2.4.2 and earlier, running on Linux 2.6.12.5 under gcc 4.0.3 with libc 2.3.5, allows local users to cause a "stack overflow," and possibly gain privileges, by running a script from a current working directory that has a long name, related to the realpath function. NOTE: this might not be a vulnerability. However, the fact that it appears in a programming language interpreter could mean that some applications are affected, although attack scenarios might be limited because the attacker might already need to cross privilege boundaries to cause an exploitable program to be placed in a directory with a long name; or, depending on the method that Python uses to determine the current working directory, setuid applications might be affected.

    Published: 22 Sept 2005
    7.5
    High

    CVE-2005-2701

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to execute arbitrary code via an XBM image file that ends in a large number of spaces instead of the expected end tag.

    Published: 22 Sept 2005
    7.5
    High

    CVE-2005-2662

    Last Modified: 16 Apr 2026

    masqmail before 0.2.18 allows remote attackers to execute arbitrary commands via crafted e-mail addresses that are not properly sanitized when creating a failed delivery message.

    Published: 21 Sept 2005
    2.1
    Low

    CVE-2005-2663

    Last Modified: 16 Apr 2026

    masqmail before 0.2.18 allows local users to overwrite arbitrary files via a symlink attack on a log file.

    Published: 21 Sept 2005
    7.5
    High

    CVE-2005-2764

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in OpenTTD before 0.4.0.1 allow attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

    Published: 21 Sept 2005
    7.5
    High

    CVE-2005-3005

    Last Modified: 16 Apr 2026

    Helpdesk Software Hesk allows remote attackers to bypass authentication for (1) admin.php and (2) admin_main.php by modifying the PHPSESSID session ID parameter or cookie.

    Published: 21 Sept 2005
    2.6
    Low

    CVE-2005-3007

    Last Modified: 16 Apr 2026

    Opera before 8.50 allows remote attackers to spoof the content type of files via a filename with a trailing "." (dot), which might allow remote attackers to trick users into processing dangerous content.

    Published: 21 Sept 2005
    7.5
    High

    CVE-2005-3008

    Last Modified: 16 Apr 2026

    Tofu 0.2 allows remote attackers to execute arbitrary Python code via crafted pickled objects, which Tofu unpickles and executes.

    Published: 21 Sept 2005
    4.3
    Medium

    CVE-2005-3009

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in CuteNews allows remote attackers to inject arbitrary web script or HTML via the mod parameter to index.php.

    Published: 21 Sept 2005
    4.6
    Medium

    CVE-2005-3013

    Last Modified: 16 Apr 2026

    Buffer overflow in liby2util in Yet another Setup Tool (YaST) for SuSE Linux 9.3 allows local users to execute arbitrary code via a long Loc entry.

    Published: 21 Sept 2005
    4.3
    Medium

    CVE-2005-3014

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Ensim webplliance allows remote attackers to inject arbitrary web script or HTML via the Login (OCW_login_username) field.

    Published: 21 Sept 2005
    4.3
    Medium

    CVE-2005-3015

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 6.5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) BaseTarget or (2) Src parameters.

    Published: 21 Sept 2005
    10
    Critical

    CVE-2005-3016

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in the WYSIWYG editor in PHP-Nuke before 7.9 Final have unknown impact and attack vectors.

    Published: 21 Sept 2005
    5
    Medium

    CVE-2005-3018

    Last Modified: 16 Apr 2026

    Apple Safari allows remote attackers to cause a denial of service (application crash) via a crafted data:// URL.

    Published: 21 Sept 2005
    4.3
    Medium

    CVE-2005-3025

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the loc parameter to (1) modcp/index.php or (2) admincp/index.php, or the ip parameter to (3) modcp/user.php or (4) admincp/usertitle.php.

    Published: 21 Sept 2005
    Unknown

    CVE-2005-3028

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-2986. Reason: This candidate is a duplicate of CVE-2005-2986. Notes: All CVE users should reference CVE-2005-2986 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Sept 2005
    7.5
    High

    CVE-2005-3003

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in NooTopList 1.0.0 release 17 allows remote attackers to execute arbitrary SQL commands via the (1) o or (2) sort parameters.

    Published: 21 Sept 2005
    5
    Medium

    CVE-2005-3006

    Last Modified: 16 Apr 2026

    The mail client in Opera before 8.50 opens attached files from the user's cache directory without warning the user, which might allow remote attackers to inject arbitrary web script and spoof attachment filenames.

    Published: 21 Sept 2005
    4.3
    Medium

    CVE-2005-3017

    Last Modified: 16 Apr 2026

    PHP file inclusion vulnerability in index.php in Content2Web 1.0.1 allows remote attackers to include arbitrary files via the show parameter, which can lead to resultant errors such as path disclosure, SQL error messages, and cross-site scripting (XSS).

    Published: 21 Sept 2005
    5
    Medium

    CVE-2005-3027

    Last Modified: 16 Apr 2026

    Sybari Antigen 8.0 SR2 does not properly filter SMTP messages, which allows remote attackers to bypass custom filter rules and send file attachments of arbitrary file types via a message with a subject of "Antigen forwarded attachment".

    Published: 21 Sept 2005
    7.5
    High

    CVE-2005-3004

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Interakt MX Shop 3.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) idp, (2) id_ctg, or (3) id_prd parameters to the pages module in index.php.

    Published: 21 Sept 2005
    7.5
    High

    CVE-2005-3010

    Last Modified: 16 Apr 2026

    Direct static code injection vulnerability in the flood protection feature in inc/shows.inc.php in CuteNews 1.4.0 and earlier allows remote attackers to execute arbitrary PHP code via the HTTP_CLIENT_IP header (Client-Ip), which is injected into data/flood.db.php.

    Published: 21 Sept 2005
    2.1
    Low

    CVE-2005-3012

    Last Modified: 16 Apr 2026

    The MasterDataCD::createImage function in masterdatacd.cpp for SimpleCDR-X 1.3.3 creates the .temp temporary directory with insecure permissions, which allows local users to read sensitive ISO images.

    Published: 21 Sept 2005
    7.5
    High

    CVE-2005-3019

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) request parameter to joinrequests.php, (2) limitnumber or (3) limitstart to user.php, (4) usertitle.php, or (5) usertools.php.

    Published: 21 Sept 2005
    4.3
    Medium

    CVE-2005-3020

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to css.php, (2) redirect parameter to index.php, (3) email parameter to user.php, (4) goto parameter to language.php, (5) orderby parameter to modlog.php, and the (6) hex, (7) rgb, or (8) expandset parameter to template.php.

    Published: 21 Sept 2005
    2.1
    Low

    CVE-2005-3021

    Last Modified: 16 Apr 2026

    image.php in vBulletin 3.0.9 and earlier allows remote attackers with access to the administrator panel to upload arbitrary files via the upload action.

    Published: 21 Sept 2005
    7.5
    High

    CVE-2005-3022

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, (2) userid parameter to user.php, (3) calendar parameter to admincalendar.php, (4) cronid parameter to cronlog.php, (5) usergroupid parameter to email.php, (6) help parameter to help.php, (7) rvt parameter to language.php, (8) keep parameter to phrase.php, or (9) updateprofilepic parameter to usertools.php.

    Published: 21 Sept 2005
    4.3
    Medium

    CVE-2005-3023

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) announcement.php, (2) admincalendar.php, (3) bbcode.php, (4) cronadmin.php, (5) email.php, (6) faq.php, (7) forum.php, (8) image.php, (9) language.php, (10) ranks.php, (11) replacement.php, (12) replacement.php, (13) template.php, (14) template.php, (15) usergroup.php, or (16) usertitle.php.

    Published: 21 Sept 2005
    7.5
    High

    CVE-2005-3024

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, the (2) thread[forumid] or (3) criteria parameters to thread.php, (4) userid parameter to user.php, the (5) calendarcustomfieldid, (6) calendarid, (7) moderatorid, (8) holidayid, (9) calendarmoderatorid, or (10) calendar[0] parameters to admincalendar.php, (11) the cronid parameter to cronlog.php, (12) user[usergroupid][0] parameter to email.php, (13) help[0] parameter to help.php, the (14) limitnumber or (15) limitstart parameter to user.php, the (16) usertitleid or (17) ids parameters to usertitle.php, (18) rvt[0] parameter to language.php, (19) keep[0] parameter to phrase.php, (20) dostyleid parameter to template.php, (21) thread[forumid] parameter to thread.php, or (22) usertools.php.

    Published: 21 Sept 2005
    7.5
    High

    CVE-2005-3029

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in AhnLab V3Pro 2004 build 6.0.0.383, V3 VirusBlock 2005 build 6.0.0.383, and V3Net for Windows Server 6.0 build 6.0.0.383 allows remote attackers to execute arbitrary code via a long filname in an ACE archive.

    Published: 21 Sept 2005
    7.5
    High

    CVE-2005-0138

    Last Modified: 16 Apr 2026

    rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not correctly allow access to anonymous clients that connect from a system whose hostname can not be determined. NOTE: while this issue occurs in a security mechanism, there is no apparent attacker role and probably does not satisfy the CVE definition of a vulnerability.

    Published: 21 Sept 2005
    7.5
    High

    CVE-2005-0139

    Last Modified: 16 Apr 2026

    Unknown vulnerability in rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not sufficiently restrict access rights for read-mostly exports, which allows attackers to conduct unauthorized activities.

    Published: 21 Sept 2005
    5
    Medium

    CVE-2005-3026

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in Alstrasoft Epay Pro 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the read parameter.

    Published: 21 Sept 2005
    5
    Medium

    CVE-2005-3030

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the archive decompression library in AhnLab V3Pro 2004 build 6.0.0.383, V3 VirusBlock 2005 build 6.0.0.383, and V3Net for Windows Server 6.0 build 6.0.0.383 allows remote attackers to write arbitrary files via a .. (dot dot) in the filename in a compressed archive.

    Published: 21 Sept 2005
    5
    Medium

    CVE-2005-2919

    Last Modified: 16 Apr 2026

    libclamav/fsg.c in Clam AntiVirus (ClamAV) before 0.87 allows remote attackers to cause a denial of service (infinite loop) via a crafted FSG packed executable.

    Published: 20 Sept 2005
    7.5
    High

    CVE-2005-2920

    Last Modified: 16 Apr 2026

    Buffer overflow in libclamav/upx.c in Clam AntiVirus (ClamAV) before 0.87 allows remote attackers to execute arbitrary code via a crafted UPX packed executable.

    Published: 20 Sept 2005
    2.1
    Low

    CVE-2005-2991

    Last Modified: 16 Apr 2026

    ncompress 4.2.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files using (1) zdiff or (2) zcmp, a different vulnerability than CVE-2004-0970.

    Published: 20 Sept 2005
    1.7
    Low

    CVE-2005-2993

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the FTP Daemon (ftpd) for HP Tru64 UNIX 4.0F PK8 and other versions up to HP Tru64 UNIX 5.1B-3, and HP-UX B.11.00, B.11.04, B.11.11, and B.11.23, allows remote authenticated users to cause a denial of service (hang).

    Published: 20 Sept 2005
    5
    Medium

    CVE-2005-2997

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in PHP Advanced Transfer Manager 1.30 allow remote attackers to read arbitrary files via ".." sequences in (1) the currentdir parameter to txt.php, or the current_dir parameter to (2) htm.php or (3) html.php.

    Published: 20 Sept 2005
    4.3
    Medium

    CVE-2005-3000

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in viewers/txt.php in PHP Advanced Transfer Manager 1.30 allow remote attackers to inject arbitrary web script or HTML via the (1) font, (2) normalfontcolor, or (3) mess[31] parameters.

    Published: 20 Sept 2005
    2.1
    Low

    CVE-2005-3001

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the "tl" driver in Solaris 10 allows local users to cause a denial of service (panic) via unknown vectors.

    Published: 20 Sept 2005
    5
    Medium

    CVE-2005-2999

    Last Modified: 16 Apr 2026

    PHP Advanced Transfer Manager 1.30 allows remote attackers to obtain sensitive PHP configuration information via a direct request to test.php.

    Published: 20 Sept 2005