CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2005-2994

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the web client for IBM Rational ClearQuest 2002.05.00 and 2002.05.20, and 2003.06.00 through 2003.06.15 before SR5, allows remote attackers to execute XML Style Sheets (XSS).

    Published: 20 Sept 2005
    7.5
    High

    CVE-2005-2996

    Last Modified: 16 Apr 2026

    Multiple heap-based and stack-based buffer overflows in certain DCOM server components in VERITAS Storage Exec Storage Exec 5.3 before Hotfix 9 and StorageCentral 5.2 before Hot Fix 2 allow remote attackers to execute arbitrary code via certain ActiveX controls.

    Published: 20 Sept 2005
    3.6
    Low

    CVE-2005-2995

    Last Modified: 16 Apr 2026

    bacula 1.36.3 and earlier allows local users to modify or read sensitive files via symlink attacks on (1) the temporary file used by autoconf/randpass when openssl is not available, or (2) the mtx.[PID] temporary file in mtx-changer.in.

    Published: 20 Sept 2005
    7.5
    High

    CVE-2005-2998

    Last Modified: 16 Apr 2026

    PHP Advanced Transfer Manager 1.30 has a default password for the administrator user, which allows remote attackers to upload and execute arbitrary PHP files.

    Published: 20 Sept 2005
    5
    Medium

    CVE-2005-3002

    Last Modified: 16 Apr 2026

    Multi-Computer Control System (MCCS) 1.0 allows remote attackers to cause a denial of service via a malformed UDP packet.

    Published: 20 Sept 2005
    4.3
    Medium

    CVE-2005-2981

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Orion 1.3.8 and 1.4.5 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting 404 error page.

    Published: 19 Sept 2005
    4.3
    Medium

    CVE-2005-2982

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in CompaqHTTPServer 2.1 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting 404 error page.

    Published: 19 Sept 2005
    7.5
    High

    CVE-2005-2983

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Oracle Reports that use Lexical References allows remote attackers to execute arbitrary SQL commands via the values in the parameter form that appears when the paramform parameter is set to yes.

    Published: 19 Sept 2005
    4.6
    Medium

    CVE-2005-2984

    Last Modified: 16 Apr 2026

    Avocent CCM console server running firmware 2.1 CCM4850 allows remote authenticated attackers to bypass port restrictions by connecting to the server via SSH and using the connect command to access the serial port.

    Published: 19 Sept 2005
    7.5
    High

    CVE-2005-2985

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search_result.php in AEwebworks aeDating Script 4.0 and earlier allows remote attackers to execute arbitrary SQL statements via the Country parameter.

    Published: 19 Sept 2005
    2.1
    Low

    CVE-2005-2990

    Last Modified: 16 Apr 2026

    AuthInfo.java in LineContol Java Client (jlc) before 0.8.1 stores sensitive information such as user passwords in log files.

    Published: 19 Sept 2005
    7.5
    High

    CVE-2005-2979

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in phpoutsourcing Noah's classifieds allows remote attackers to execute arbitrary SQL commands via the rollid parameter.

    Published: 19 Sept 2005
    7.5
    High

    CVE-2005-2987

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in login.php in Digital Scribe 1.4 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 19 Sept 2005
    4.3
    Medium

    CVE-2005-2980

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in phpoutsourcing Noah's classifieds 1.3 allows remote attackers to inject arbitrary web script or HTML via the rollid parameter.

    Published: 19 Sept 2005
    5
    Medium

    CVE-2005-2988

    Last Modified: 16 Apr 2026

    HP LaserJet 2430, and possibly other printers that use Jetdirect controls, stores information about recently printed documents without proper protection, which could allow remote attackers to obtain sensitive information via SNMP.

    Published: 19 Sept 2005
    7.5
    High

    CVE-2005-2986

    Last Modified: 16 Apr 2026

    The v3flt2k.sys driver in AhnLab V3Pro 2004 Build 6.0.0.383, V3 VirusBlock 2005 Build 6.0.0.383, V3Net for Windows Server 6.0 Build 6.0.0.383 does not properly validate the source of the DeviceIoControl commands, which allows remote attackers to gain privileges.

    Published: 19 Sept 2005
    7.5
    High

    CVE-2005-2989

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in DeluxeBB 1.0 and 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) tid parameter to topic.php, the uid parameter to (2) misc.php or (3) pm.php, or the fid parameter to (3) forums.php or (4) newpost.php.

    Published: 19 Sept 2005
    4.6
    Medium

    CVE-2005-2944

    Last Modified: 16 Apr 2026

    The perform_file_save function in GNOME Workstation Command Center (gwcc) 0.9.6 and earlier allows local users to create and overwrite arbitrary files via a symlink attack on the gwcc_out.txt temporary file.

    Published: 16 Sept 2005
    2.1
    Low

    CVE-2005-2948

    Last Modified: 16 Apr 2026

    KillProcess 2.20 and earlier allows local users to bypass kill list restrictions by launching multiple processes at the same time, which are not all killed by KillProcess.

    Published: 16 Sept 2005
    7.5
    High

    CVE-2005-2949

    Last Modified: 16 Apr 2026

    pam_per_user before 0.4 does not verify if the user name changes between authentication attempts and uses the same subrequest handle, which allows remote attackers or local users to login as other users by using certain applications that allow the username to be changed during authentication, such as /bin/login.

    Published: 16 Sept 2005
    4.3
    Medium

    CVE-2005-2950

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Sawmill 7.0.0 through 7.1.13 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP GET request.

    Published: 16 Sept 2005
    7.5
    High

    CVE-2005-2951

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in security.inc.php in AzDGDatingLite 2.1.3, and possibly earlier versions, allows remote attackers to execute arbitrary PHP commands via ".." sequences and "%00" (trailing null byte) characters in the l parameter, which is used in an include_once statement.

    Published: 16 Sept 2005
    5
    Medium

    CVE-2005-2952

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in s.pl in Subscribe Me Pro 2.044.09P and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the l parameter.

    Published: 16 Sept 2005
    5.1
    Medium

    CVE-2005-2947

    Last Modified: 16 Apr 2026

    Buffer overflow in KillProcess 2.20 and earlier allows user-assisted attackers to execute arbitrary code via an exe file with a long FileDescription in the version resource.

    Published: 16 Sept 2005
    5
    Medium

    CVE-2005-2956

    Last Modified: 16 Apr 2026

    ATutor 1.5.1, and possibly earlier versions, stores temporary chat logs under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain user chat conversations via direct requests to those files.

    Published: 16 Sept 2005
    7.5
    High

    CVE-2005-2957

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in AVIRA Desktop for Windows 1.00.00.68 with AVPACK32.DLL 6.31.0.3, when archive scanning is enabled, allows remote attackers to execute arbitrary code via a long filename in an ACE archive.

    Published: 16 Sept 2005
    4.6
    Medium

    CVE-2005-2955

    Last Modified: 16 Apr 2026

    config.inc.php in ATutor 1.5.1, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which allows authenticated administrators or educators to execute arbitrary code by uploading files with other executable extensions such as .inc, .php4, or others.

    Published: 16 Sept 2005
    7.5
    High

    CVE-2005-2877

    Last Modified: 16 Apr 2026

    The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary code via shell metacharacters, as demonstrated via the rev parameter to TWikiUsers.

    Published: 16 Sept 2005
    7.5
    High

    CVE-2005-2946

    Last Modified: 16 Apr 2026

    The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certificates with a valid certificate authority signature.

    Published: 16 Sept 2005
    7.5
    High

    CVE-2005-2954

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in password_reminder.php in ATutor before 1.5.1 pl1 allows remote attackers to execute arbitrary SQL commands via the email field.

    Published: 16 Sept 2005
    4.6
    Medium

    CVE-2005-2657

    Last Modified: 16 Apr 2026

    Unknown vulnerability in common-lisp-controller 4.18 and earlier allows local users to gain privileges by compiling arbitrary code in the cache directory, which is executed by another user if the user has not run Common Lisp before.

    Published: 16 Sept 2005
    2.1
    Low

    CVE-2005-2945

    Last Modified: 16 Apr 2026

    arc 5.21j and earlier create temporary files with world-readable permissions, which allows local users to read sensitive information from files created by (1) arc (arc.c) or (2) marc (marc.c).

    Published: 16 Sept 2005
    4.3
    Medium

    CVE-2005-2953

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in merchant.mvc in MIVA Merchant 5 allows remote attackers to inject arbitrary web script or HTML via the Customer_Login parameter.

    Published: 16 Sept 2005
    7.5
    High

    CVE-2005-2799

    Last Modified: 16 Apr 2026

    Buffer overflow in apply.cgi in Linksys WRT54G 3.01.03, 3.03.6, and possibly other versions before 4.20.7, allows remote attackers to execute arbitrary code via a long HTTP POST request.

    Published: 15 Sept 2005
    7.5
    High

    CVE-2005-2658

    Last Modified: 16 Apr 2026

    Buffer overflow in utility.cpp in Turquoise SuperStat (turqstat) 2.2.4 and earlier might allow remote NNTP servers to execute arbitrary code via a date with a long month.

    Published: 15 Sept 2005
    5
    Medium

    CVE-2005-2918

    Last Modified: 16 Apr 2026

    The open_cmd_tube function in mount.c for gtkdiskfree 1.9.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the gtkdiskfree temporary file.

    Published: 15 Sept 2005
    4.6
    Medium

    CVE-2005-2935

    Last Modified: 16 Apr 2026

    Unquoted Windows search path vulnerability in Microsoft AntiSpyware might allow local users to execute code via a malicious c:\program.exe file, which is run by AntiSpywareMain.exe when it attempts to execute gsasDtServ.exe. NOTE: it is not clear whether this overlaps CVE-2005-2940.

    Published: 15 Sept 2005
    5
    Medium

    CVE-2005-2917

    Last Modified: 16 Apr 2026

    Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).

    Published: 15 Sept 2005
    2.1
    Low

    CVE-2005-2879

    Last Modified: 16 Apr 2026

    Advansysperu Software USB Lock Auto-Protect (AP) 1.5 uses a weak encryption scheme to encrypt passwords, which allows local users to gain sensitive information and bypass USB interface protection.

    Published: 14 Sept 2005
    7.5
    High

    CVE-2005-2880

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in phpCommunityCalendar 4.0.3, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via the (1) login field in login.php or (2) LocationID parameter to week.php.

    Published: 14 Sept 2005
    7.5
    High

    CVE-2005-2881

    Last Modified: 16 Apr 2026

    phpCommunityCalendar 4.0.3 allows remote attackers to bypass authentication and gain unauthorized access via a direct request to the admin directory.

    Published: 14 Sept 2005
    Unknown

    CVE-2005-2883

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-2855. Reason: This candidate is a duplicate of CVE-2005-2855. Notes: All CVE users should reference CVE-2005-2855 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 14 Sept 2005
    5
    Medium

    CVE-2005-2887

    Last Modified: 16 Apr 2026

    MAXdev MD-Pro 1.0.73, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to (1) wiki.php, (2) AutoTheme directory, (3) Blocks directory, (4) admin.php, (5) pnadmin.php, or (6) Topics directory, which reveal the path in an error message.

    Published: 14 Sept 2005
    7.5
    High

    CVE-2005-2888

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) Preview Release 2 allow remote attackers to execute arbitrary SQL commands via the (1) fid parameter to misc.php or (2) Content-Disposition field in the HTTP header to newreply.php.

    Published: 14 Sept 2005
    7.5
    High

    CVE-2005-2889

    Last Modified: 16 Apr 2026

    Check Point NGX R60 does not properly verify packets against the predefined service group "CIFS" rule, which allows remote attackers to bypass intended restrictions.

    Published: 14 Sept 2005
    4.6
    Medium

    CVE-2005-2890

    Last Modified: 16 Apr 2026

    SecureOL VE2 1.05.1008 does not properly restrict public access to physical memory, which allows local users to bypass intended restrictions and gain access to the secured environment via direct access to the PhysicalMemory device.

    Published: 14 Sept 2005
    6.4
    Medium

    CVE-2005-2891

    Last Modified: 16 Apr 2026

    WebArchiveX.dll 5.5.0.76 installed before September 6th, 2005 is marked safe for scripting by default, which allows remote attackers to read or write to arbitrary files via the (1) MakeArchive or (2) MakeArchiveStr methods.

    Published: 14 Sept 2005
    5
    Medium

    CVE-2005-2895

    Last Modified: 16 Apr 2026

    setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to obtain sensitive information via a %00 (a null byte) in the u parameter, which reveals the path in an error message.

    Published: 14 Sept 2005
    7.5
    High

    CVE-2005-2896

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in WEB//NEWS 1.4 allows remote attackers to execute arbitrary SQL commands via the (1) wn_userpw parameter to startup.php, (2) cat, (3) id, or (4) stof parameter to news.php, or (5) id parameter to print.php.

    Published: 14 Sept 2005
    5
    Medium

    CVE-2005-2897

    Last Modified: 16 Apr 2026

    WEB//NEWS 1.4 allows remote attackers to obtain sensitive information via a direct request to files in the actions directory, which reveal the path in an error message, as demonstrated using cat.add.php.

    Published: 14 Sept 2005