CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2005-2849

    Last Modified: 16 Apr 2026

    Argument injection vulnerability in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to (1) read portions of source code via the -f option to Dig (dig_device.cgi), (2) determine file existence via the -r argument to Tcpdump (tcpdump_device.cgi) or (3) modify files in the cgi-bin directory via the -w argument to Tcpdump.

    Published: 8 Sept 2005
    5
    Medium

    CVE-2005-2852

    Last Modified: 16 Apr 2026

    Unknown vulnerability in CIFS.NLM in Novell Netware 6.5 SP2 and SP3, 5.1, and 6.0 allows remote attackers to cause a denial of service (ABEND) via an incorrect password length, as exploited by the "worm.rbot.ccc" worm.

    Published: 8 Sept 2005
    2.1
    Low

    CVE-2005-2868

    Last Modified: 16 Apr 2026

    ZipTorrent 1.3.7.3 stores sensitive information in plaintext in the pref.txt file, which allows local users to obtain sensitive information such as proxy server information and passwords.

    Published: 8 Sept 2005
    4.6
    Medium

    CVE-2005-2490

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the sendmsg function call in the Linux kernel 2.6 before 2.6.13.1 allows local users to execute arbitrary code by calling sendmsg and modifying the message contents in another thread.

    Published: 8 Sept 2005
    5.1
    Medium

    CVE-2005-2495

    Last Modified: 16 Apr 2026

    Multiple integer overflows in XFree86 before 4.3.0 allow user-assisted attackers to execute arbitrary code via a crafted pixmap image.

    Published: 8 Sept 2005
    4.3
    Medium

    CVE-2005-2836

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Phorum 5.0.17a and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to register.php or (2) a signature of a logged-in user in "My Control Center," which is not properly handled by control.php.

    Published: 7 Sept 2005
    5
    Medium

    CVE-2005-2817

    Last Modified: 16 Apr 2026

    Simple Machines Forum (SMF) 1-0-5 and earlier supports the use of URLs for avatar images, which allows remote attackers to monitor sensitive information of forum visitors such as IP address and user agent, as demonstrated using a PHP script on a malicious server.

    Published: 7 Sept 2005
    7.5
    High

    CVE-2005-2808

    Last Modified: 16 Apr 2026

    frox 0.7.16 and 0.7.17 does not properly parse certain Deny ACLs, which might allow attackers to bypass intended restrictions and access blocked hosts.

    Published: 7 Sept 2005
    10
    Critical

    CVE-2005-2840

    Last Modified: 16 Apr 2026

    Multiple unknown vulnerabilities in MAXdev MD-Pro 1.0.72 and earlier have unknown impact and unspecified attack vectors, in one or more of the (1) Download, (2) Search, (3) Web links, (4) Blocks, (5) Messages, (6) News, (7) Comments, (8) Settings, (9) Stats or (10) subjects modules.

    Published: 7 Sept 2005
    7.5
    High

    CVE-2005-2838

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in login.php in myBloggie 2.1.3-beta and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 7 Sept 2005
    7.5
    High

    CVE-2005-2819

    Last Modified: 16 Apr 2026

    DownFile 1.3 allows remote attackers to gain administrator privileges via a direct request to (1) update.php, (2) del.php, and (3) add_form.php.

    Published: 7 Sept 2005
    2.1
    Low

    CVE-2005-2809

    Last Modified: 16 Apr 2026

    silc daemon (silcd.c) in Secure Internet Live Conferencing (SILC) 1.0 and earlier allows local users to overwrite arbitrary files via a symlink attack on the silcd.[PID].stats temporary file.

    Published: 7 Sept 2005
    7.5
    High

    CVE-2005-2837

    Last Modified: 16 Apr 2026

    Multiple eval injection vulnerabilities in PlainBlack Software WebGUI before 6.7.3 allow remote attackers to execute arbitrary Perl code via (1) Help.pm, (2) International.pm, or (3) WebGUI.pm.

    Published: 7 Sept 2005
    4.3
    Medium

    CVE-2005-2818

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in DownFile 1.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter to (1) email.php,(2) index.php, (3) del.php, or (4) add_form.php.

    Published: 7 Sept 2005
    4.6
    Medium

    CVE-2005-2811

    Last Modified: 16 Apr 2026

    Untrusted search path vulnerability in Net-SNMP 5.2.1.2 and earlier, on Gentoo Linux, installs certain Perl modules with an insecure DT_RPATH, which could allow local users to gain privileges.

    Published: 7 Sept 2005
    7.5
    High

    CVE-2005-2812

    Last Modified: 16 Apr 2026

    man2web allows remote attackers to execute arbitrary commands via -P arguments.

    Published: 7 Sept 2005
    5
    Medium

    CVE-2005-2813

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files via ".." sequences and "%00" (trailing null byte) characters in the id parameter to the read mod in index.php.

    Published: 7 Sept 2005
    4.3
    Medium

    CVE-2005-2814

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the usr parameter in a vis_reg operation to index.php.

    Published: 7 Sept 2005
    6.4
    Medium

    CVE-2005-2815

    Last Modified: 16 Apr 2026

    print.php in FlatNuke 2.5.6 allows remote attackers to obtain sensitive information (path disclosure on error) or cause a denial of service (resource consumption) via an MS-DOS device name in the news parameter to print.php, such as (1) AUX, (2) CON, (3) PRN, (4) COM1, or (5) LPT1.

    Published: 7 Sept 2005
    4.3
    Medium

    CVE-2005-2816

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Greymatter allows remote attackers to inject arbitrary web script or HTML via a post comment, which is recorded in a log file but not properly handled when the administrator uses "View Control Panel Log" to read the log file.

    Published: 7 Sept 2005
    7.2
    High

    CVE-2005-2810

    Last Modified: 16 Apr 2026

    Multiple stack-based buffer overflows in urban before 1.5.3 allow local users to gain privileges via a long HOME environment variable to (1) config.cc, (2) game.cc, (3) highscor.cc, or (4) meny.cc.

    Published: 7 Sept 2005
    4.3
    Medium

    CVE-2005-2820

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via an e-mail message containing Internet Explorer "Conditional Comments" such as "[if]" and "[endif]".

    Published: 7 Sept 2005
    4.3
    Medium

    CVE-2005-2839

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in MAXdev MD-Pro 1.0.72 allow remote attackers to inject arbitrary web script or HTML via (1) dl-search.php or (2) wl-search.php.

    Published: 7 Sept 2005
    7.2
    High

    CVE-2005-2807

    Last Modified: 16 Apr 2026

    frox 0.7.18, when running setuid root, does not properly drop privileges when reading a configuration file, which allows local users to read portions of arbitrary files via the -f command line option.

    Published: 7 Sept 2005
    4.3
    Medium

    CVE-2005-2803

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Hiki 0.8.1 to 0.8.2 allows remote attackers to inject arbitrary web script or HTML via a page name in a Login link, a different vulnerability than CVE-2005-2336.

    Published: 6 Sept 2005
    4.3
    Medium

    CVE-2005-2336

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Hiki 0.8.0 to 0.8.2 allows remote attackers to inject arbitrary web script or HTML via "missing pages" in which the page name is not properly escaped, a different vulnerability than CVE-2005-2803.

    Published: 6 Sept 2005
    2.1
    Low

    CVE-2005-2656

    Last Modified: 16 Apr 2026

    Polygen before 1.0.6 generates precompiled grammar objects with world-writable permissions, which allows local users to cause a denial of service (disk consumption) and possibly perform other unauthorized activities.

    Published: 6 Sept 2005
    7.5
    High

    CVE-2005-2763

    Last Modified: 16 Apr 2026

    Multiple format string vulnerabilities in OpenTTD before 0.4.0.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

    Published: 6 Sept 2005
    5
    Medium

    CVE-2005-2797

    Last Modified: 16 Apr 2026

    OpenSSH 4.0, and other versions before 4.2, does not properly handle dynamic port forwarding ("-D" option) when a listen address is not provided, which may cause OpenSSH to enable the GatewayPorts functionality.

    Published: 6 Sept 2005
    5
    Medium

    CVE-2005-2805

    Last Modified: 16 Apr 2026

    forum_post.php in e107 0.6 allows remote attackers to post to non-existent forums by modifying the forum number.

    Published: 6 Sept 2005
    5
    Medium

    CVE-2005-2806

    Last Modified: 16 Apr 2026

    client.cpp in BNBT EasyTracker 7.7r3.2004.10.27 and earlier allows remote attackers to cause a denial of service (application hang) via an HTTP header containing only a ":" (colon), possibly leading to an integer signedness error due to a missing field name or value.

    Published: 6 Sept 2005
    Unknown

    CVE-2005-2802

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-2872, CVE-2005-2873. Reason: this candidate's description originally combined two separate issues. Notes: All CVE users should consult CVE-2005-2872 and CVE-2005-2873 to determine the appropriate identifier for the issue

    Published: 6 Sept 2005
    7.5
    High

    CVE-2005-2968

    Last Modified: 16 Apr 2026

    Firefox 1.0.6 and Mozilla 1.7.10 allows attackers to execute arbitrary commands via shell metacharacters in a URL that is provided to the browser on the command line, which is sent unfiltered to bash.

    Published: 6 Sept 2005
    7.2
    High

    CVE-2005-2494

    Last Modified: 16 Apr 2026

    kcheckpass in KDE 3.2.0 up to 3.4.2 allows local users to gain root access via a symlink attack on lock files.

    Published: 5 Sept 2005
    5
    Medium

    CVE-2005-3351

    Last Modified: 16 Apr 2026

    SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl.

    Published: 5 Sept 2005
    7.5
    High

    CVE-2005-2790

    Last Modified: 16 Apr 2026

    BFCommand & Control Server Manager BFCC 1.22_A and earlier, and BFVCC 2.14_B and earlier, relies on the client to enforce permissions and perform actions such as disconnections, which allows remote attackers to bypass administrative restrictions via a modified client.

    Published: 2 Sept 2005
    7.5
    High

    CVE-2005-2782

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute arbitrary PHP code via an "ftp://" URL in the alpath parameter, which bypasses the incomplete blacklist that only checks for "http" and "https" URLs.

    Published: 2 Sept 2005
    4.3
    Medium

    CVE-2005-2776

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Looking Glass 20040427 allow remote attackers to inject arbitrary web script or HTML via the (1) version[fullname], (2) version[homepage], or (3) version[no] parameter to footer.php, or the (4) version[fullname], (5) version[no], (6) version[author], (7) version[email] parameter to header.php.

    Published: 2 Sept 2005
    5
    Medium

    CVE-2005-2774

    Last Modified: 16 Apr 2026

    Format string vulnerability in Lithium II mod 1.24 for Quake 2 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in the nickname.

    Published: 2 Sept 2005
    7.5
    High

    CVE-2005-2768

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the Sophos Antivirus Library, as used by Sophos Antivirus, PureMessage, MailMonitor, and other products, allows remote attackers to execute arbitrary code via a Visio file with a crafted sub record length.

    Published: 2 Sept 2005
    7.5
    High

    CVE-2005-2767

    Last Modified: 16 Apr 2026

    Buffer overflow in LeapFTP allows remote attackers to execute arbitrary code via a long Host string in a Site Queue (.lsq) file.

    Published: 2 Sept 2005
    9.8
    Critical

    CVE-2005-2773

    Last Modified: 16 Apr 2026

    HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.

    Published: 2 Sept 2005
    7.5
    High

    CVE-2005-2793

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to execute arbitrary PHP code via the custom_welcome_page parameter.

    Published: 2 Sept 2005
    5
    Medium

    CVE-2005-2791

    Last Modified: 16 Apr 2026

    BFCommand & Control Server Manager BFCC 1.22_A and earlier, and BFVCC 2.14_B and earlier, allows remote attackers to cause a denial of service (refused new connections) via a series of connections and disconnections without sending the login command.

    Published: 2 Sept 2005
    7.5
    High

    CVE-2005-2784

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the login function for the administration login panel in cosmoshop 8.10.78 allows remote attackers to execute arbitrary SQL commands and bypass authentication via unspecified vectors.

    Published: 2 Sept 2005
    4.3
    Medium

    CVE-2005-2783

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML via nested, malformed URL BBCode tags.

    Published: 2 Sept 2005
    4.3
    Medium

    CVE-2005-2780

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Land Down Under (LDU) allows remote attackers to inject arbitrary web script or HTML via a signature.

    Published: 2 Sept 2005
    7.5
    High

    CVE-2005-2778

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in member.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL statements via the fid parameter.

    Published: 2 Sept 2005
    7.5
    High

    CVE-2005-2775

    Last Modified: 16 Apr 2026

    php_api.php in phpWebNotes 2.0.0 uses the extract function to modify key variables such as $t_path_core, which leads to a PHP file inclusion vulnerability that allows remote attackers to execute arbitrary PHP code via the t_path_core parameter.

    Published: 2 Sept 2005
    10
    Critical

    CVE-2005-2771

    Last Modified: 16 Apr 2026

    WRQ Reflection for Secure IT Windows Server 6.0 (formerly known as F-Secure SSH server) processes access and deny lists in a case-sensitive manner, when previous versions were case-insensitive, which might allow remote attackers to bypass intended restrictions and login to accounts that should be denied.

    Published: 2 Sept 2005