CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2005-2585

    Last Modified: 16 Apr 2026

    Mentor ADSL-FR4II router running firmware 2.00.0111 allows remote attackers to cause a denial of service (active TCP connections state table consumption) via a large number of connections, such as a port scan.

    Published: 16 Aug 2005
    2.1
    Low

    CVE-2005-2586

    Last Modified: 16 Apr 2026

    Mentor ADSL-FR4II router running firmware 2.00.0111 stores the web administration password in cleartext in the backup configuration file, which allows local users to obtain sensitive information.

    Published: 16 Aug 2005
    7.5
    High

    CVE-2005-2587

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in emailvalidate.php in PHPTB Topic Boards 2.0 allows remote attackers to execute arbitrary SQL commands via the mid parameter.

    Published: 16 Aug 2005
    7.5
    High

    CVE-2005-2561

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in MYFAQ 1.0 allow remote attackers to execute arbitrary SQL commands via the Theme parameter to (1) affichagefaq.php3, (2) choixsoustheme.php3, (3) consultation.php3, (4) insfaq.php3, (5) inssoustheme.php3, (6) instheme.php3, (7) saisiefaqtotale.php3, (8) saisiesoustheme.php3, or (9) voirfaq.php3, the SousTheme parameter to (10) affichagefaq.php3, (11) consultation.php3, (12) insfaq.php3, (13) inssoustheme.php3, (14) saisiefaq.php3, (15) saisiefaqtotale.php3, or (16) voirfaq.php3, the Faq parameter to (17) saisiefaq.php3, (18) voirfaq.php3, or (19) inssolution.php3, or (20) question parameter to affichagefaq.php3.

    Published: 16 Aug 2005
    7.5
    High

    CVE-2005-2567

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in SysCP 1.2.10 and earlier allows remote attackers to execute arbitrary PHP code via the language parameter.

    Published: 16 Aug 2005
    5
    Medium

    CVE-2005-2576

    Last Modified: 16 Apr 2026

    CaLogic 1.22, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to (1) doclsqlres.php, (2) clmcpreload.php, (3) viewhistlog.php, (4) mcconfig.php, (5) doclsqlbak.php, (6) defcalsel.php, or (7) cl_minical.php, which reveals the path in an error message.

    Published: 16 Aug 2005
    5
    Medium

    CVE-2005-2357

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

    Published: 16 Aug 2005
    7.5
    High

    CVE-2005-2559

    Last Modified: 16 Apr 2026

    doping.php in ePing plugin 1.02 and earlier for e107 portal allows remote attackers to execute arbitrary code or overwrite files via (1) shell metacharacters in the eping_count parameter or (2) restricted shell metacharacters such as ">" and "&" in the eping_host parameter, which is not handled by the validation function.

    Published: 16 Aug 2005
    4.3
    Medium

    CVE-2005-2560

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.cfm in CFBB 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 16 Aug 2005
    7.5
    High

    CVE-2005-2562

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Gravity Board X (GBX) 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the login field.

    Published: 16 Aug 2005
    7.5
    High

    CVE-2005-2564

    Last Modified: 16 Apr 2026

    Direct static code injection vulnerability in editcss.php in Gravity Board X (GBX) 1.1 allows remote attackers to execute arbitrary PHP code, HTML, and script via the csscontent parameter, which is directly inserted into the gbxfinal.css file.

    Published: 16 Aug 2005
    7.5
    High

    CVE-2005-2568

    Last Modified: 16 Apr 2026

    Eval injection vulnerability in the template engine for SysCP 1.2.10 and earlier allows remote attackers to execute arbitrary PHP code via a string containing the code within "{" and "}" (curly bracket) characters, which are processed by the PHP eval function.

    Published: 16 Aug 2005
    4.3
    Medium

    CVE-2005-2569

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in FunkBoard 0.66CF, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the fbusername or fbpassword parameter to (1) editpost.php, (2) prefs.php, (3) newtopic.php, (4) reply.php, or (5) profile.php, the (6) fbusername, (7) fmail, (8) www, (9) icq, (10) yim, (11) location, (12) sex, (13) interebbies, (14) sig or (15) aim parameter to register.php, or (16) subject parameter to newtopic.php.

    Published: 16 Aug 2005
    7.5
    High

    CVE-2005-2583

    Last Modified: 16 Apr 2026

    Mentor ADSL-FR4II router running firmware 2.00.0111 has an undocumented web server running on TCP port 5678, which allows local users to gain access.

    Published: 16 Aug 2005
    7.2
    High

    CVE-2005-2584

    Last Modified: 16 Apr 2026

    The web administration interface in Mentor ADSL-FR4II router running firmware 2.00.0111 does not set a default password, which allows local users to gain access.

    Published: 16 Aug 2005
    4.6
    Medium

    CVE-2005-2558

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the init_syms function in MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta allows remote authenticated users who can create user-defined functions to execute arbitrary code via a long function_name field.

    Published: 16 Aug 2005
    7.5
    High

    CVE-2005-2566

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Open Bulletin Board (OpenBB) allow remote attackers to execute arbitrary SQL commands via the (1) FID parameter to board.php or (2) UID parameter to member.php.

    Published: 16 Aug 2005
    7.5
    High

    CVE-2005-2580

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 with Security Patch allow remote attackers to execute arbitrary SQL commands via the Username field in (1) index.php or (2) member.php, action parameter to (3) search.php or (4) member.php, or (5) polloptions parameter to polls.php.

    Published: 16 Aug 2005
    3.6
    Low

    CVE-2005-2582

    Last Modified: 16 Apr 2026

    Kaspersky Anti-Virus for Unix/Linux File Servers 5.0-5 uses world-writable permissions for the (1) log and (2) license directory, which allows local users to delete log files, append to arbitrary files via a symlink attack on kavmonitor.log, or delete license keys and prevent keepup2date from properly executing.

    Published: 16 Aug 2005
    5
    Medium

    CVE-2005-2574

    Last Modified: 16 Apr 2026

    xmb.php in XMB Forum 1.9.1 extracts and defines all provided variables, which allows remote attackers to modify arbitrary server variables such as _SERVER[REMOTE_ADDR].

    Published: 16 Aug 2005
    7.5
    High

    CVE-2005-2470

    Last Modified: 16 Apr 2026

    Buffer overflow in a "core application plug-in" for Adobe Reader 5.1 through 7.0.2 and Acrobat 5.0 through 7.0.2 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.

    Published: 16 Aug 2005
    5
    Medium

    CVE-2005-1527

    Last Modified: 16 Apr 2026

    Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is inserted into an eval function call.

    Published: 15 Aug 2005
    2.1
    Low

    CVE-2005-2672

    Last Modified: 16 Apr 2026

    pwmconfig in LM_sensors before 2.9.1 creates temporary files insecurely, which allows local users to overwrite arbitrary files via a symlink attack on the fancontrol temporary file.

    Published: 14 Aug 2005
    7.5
    High

    CVE-2005-2498

    Last Modified: 16 Apr 2026

    Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.

    Published: 14 Aug 2005
    7.5
    High

    CVE-2005-2547

    Last Modified: 16 Apr 2026

    security.c in hcid for BlueZ 2.16, 2.17, and 2.18 allows remote attackers to execute arbitrary commands via shell metacharacters in the Bluetooth device name when invoking the PIN helper.

    Published: 12 Aug 2005
    2.1
    Low

    CVE-2005-2554

    Last Modified: 16 Apr 2026

    The web server for Network Associates ePolicy Orchestrator Agent 3.5.0 (patch 3) uses insecure permissions for the "Common Framework\Db" folder, which allows local users to read arbitrary files by creating a subfolder in the EPO agent web root directory.

    Published: 12 Aug 2005
    7.5
    High

    CVE-2005-2551

    Last Modified: 16 Apr 2026

    Buffer overflow in dhost.exe in iMonitor for Novell eDirectory 8.7.3 on Windows allows attackers to cause a denial of service (crash) and obtain access to files via unknown vectors.

    Published: 12 Aug 2005
    5
    Medium

    CVE-2005-2548

    Last Modified: 16 Apr 2026

    vlan_dev.c in the VLAN code for Linux kernel 2.6.8 allows remote attackers to cause a denial of service (kernel oops from null dereference) via certain UDP packets that lead to a function call with the wrong argument, as demonstrated using snmpwalk on snmpd.

    Published: 12 Aug 2005
    7.5
    High

    CVE-2005-2552

    Last Modified: 16 Apr 2026

    Unknown vulnerability in HP ProLiant DL585 servers running Integrated Lights Out (ILO) firmware before 1.81 allows attackers to access server controls when the server is "powered down."

    Published: 12 Aug 2005
    2.1
    Low

    CVE-2005-2499

    Last Modified: 16 Apr 2026

    slocate before 2.7 does not properly process very long paths, which allows local users to cause a denial of service (updatedb exit and incomplete slocate database) via a certain crafted directory structure.

    Published: 12 Aug 2005
    7.5
    High

    CVE-2005-1984

    Last Modified: 16 Apr 2026

    Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.

    Published: 10 Aug 2005
    5.1
    Medium

    CVE-2005-1988

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to execute arbitrary code via a web site or an HTML e-mail containing a crafted JPEG image that causes memory corruption, aka "JPEG Image Rendering Memory Corruption Vulnerability".

    Published: 10 Aug 2005
    5
    Medium

    CVE-2005-2537

    Last Modified: 16 Apr 2026

    FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via a direct request to structure.php.

    Published: 10 Aug 2005
    4.3
    Medium

    CVE-2005-2539

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in FlatNuke 2.5.5 and possibly earlier versions allow remote attackers to inject arbitrary web script or HTML via the (1) bodycolor, (2) backimage, (3) theme, or (4) logo parameter to structure.php, (5) admin, (6) admin_mail, or (7) back parameter to footer.php, or (8) the message body in a news post.

    Published: 10 Aug 2005
    5
    Medium

    CVE-2005-2540

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via an ASCII char 13 (carriage return) in the signature field, which is injected into a PHP script without a preceding comment character, which can then be executed by a direct request.

    Published: 10 Aug 2005
    7.5
    High

    CVE-2005-2536

    Last Modified: 16 Apr 2026

    pstotext before 1.8g does not properly use the "-dSAFER" option when calling Ghostscript to extract plain text from PostScript and PDF files, which allows remote attackers to execute arbitrary commands via a malicious PostScript file.

    Published: 10 Aug 2005
    5
    Medium

    CVE-2005-2546

    Last Modified: 16 Apr 2026

    Arab Portal 2.0 allows remote attackers to obtain sensitive information via a long (1) username or (2) password, which reveals the path in an error message when the undefined "errmsg" function is called.

    Published: 10 Aug 2005
    7.5
    High

    CVE-2005-0058

    Last Modified: 16 Apr 2026

    Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to elevate privileges or execute arbitrary code via a crafted message.

    Published: 10 Aug 2005
    5.1
    Medium

    CVE-2005-1990

    Last Modified: 16 Apr 2026

    Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, including (1) devenum.dll, (2) diactfrm.dll, (3) wmm2filt.dll, (4) fsusd.dll, (5) dmdskmgr.dll, (6) browsewm.dll, (7) browseui.dll, (8) shell32.dll, (9) mshtml.dll, (10) inetcfg.dll, (11) infosoft.dll, (12) query.dll, (13) syncui.dll, (14) clbcatex.dll, (15) clbcatq.dll, (16) comsvcs.dll, and (17) msconf.dll, which causes memory corruption, aka "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2087.

    Published: 10 Aug 2005
    7.5
    High

    CVE-2005-2535

    Last Modified: 16 Apr 2026

    Buffer overflow in the Discovery Service in BrightStor ARCserve Backup 9.0 through 11.1 allows remote attackers to execute arbitrary commands via a large packet to TCP port 41523, a different vulnerability than CVE-2005-0260.

    Published: 10 Aug 2005
    5
    Medium

    CVE-2005-2538

    Last Modified: 16 Apr 2026

    FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via (1) a null byte or (2) an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1 in the mod parameter.

    Published: 10 Aug 2005
    4.3
    Medium

    CVE-2005-2545

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PHPOpenChat 3.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content parameter to profile.php and profile_misc.php, (3) the profile fields in userpage.php, (4) subject or (5) body in mail.php, or (8) disinvited_chatter or (7) invited_chatter parameter to invite.php.

    Published: 10 Aug 2005
    2.1
    Low

    CVE-2005-1981

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.

    Published: 10 Aug 2005
    3.6
    Low

    CVE-2005-1982

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.

    Published: 10 Aug 2005
    10
    Critical

    CVE-2005-1983

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.

    Published: 10 Aug 2005
    5
    Medium

    CVE-2005-2543

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in wce.download.php in Comdev eCommerce 3.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the download parameter.

    Published: 10 Aug 2005
    5
    Medium

    CVE-2005-2544

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in config.php in Comdev eCommerce 3.0 allows remote attackers to execute arbitrary PHP code via the path[docroot] parameter.

    Published: 10 Aug 2005
    5
    Medium

    CVE-2005-1218

    Last Modified: 16 Apr 2026

    The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.

    Published: 10 Aug 2005
    7.5
    High

    CVE-2005-1989

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when browsing from a web site to a web folder view using WebDAV, aka "Web Folder Behaviors Cross-Domain Vulnerability".

    Published: 10 Aug 2005
    5
    Medium

    CVE-2005-2542

    Last Modified: 16 Apr 2026

    Invision Power Board (IPB) 1.0.3 allows remote attackers to inject arbitrary web script or HTML via an attachment, which is automatically downloaded and processed as HTML.

    Published: 10 Aug 2005