CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2005-2549

    Last Modified: 16 Apr 2026

    Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers.

    Published: 10 Aug 2005
    7.5
    High

    CVE-2005-2550

    Last Modified: 16 Apr 2026

    Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entries such as task lists, which are not properly handled when the user selects the Calendars tab.

    Published: 10 Aug 2005
    2.1
    Low

    CVE-2005-2104

    Last Modified: 16 Apr 2026

    sysreport before 1.3.7 allows local users to obtain sensitive information via a symlink attack on a temporary directory.

    Published: 9 Aug 2005
    2.1
    Low

    CVE-2005-2097

    Last Modified: 16 Apr 2026

    xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information.

    Published: 9 Aug 2005
    7.5
    High

    CVE-2005-2500

    Last Modified: 16 Apr 2026

    Buffer overflow in the xdr_xcode_array2 function in xdr.c in Linux kernel 2.6.12, as used in SuSE Linux Enterprise Server 9, might allow remote attackers to cause a denial of service and possibly execute arbitrary code via crafted XDR data for the nfsacl protocol.

    Published: 8 Aug 2005
    5
    Medium

    CVE-2005-2102

    Last Modified: 16 Apr 2026

    The AIM/ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) via a filename that contains invalid UTF-8 characters.

    Published: 8 Aug 2005
    9.8
    Critical

    CVE-2005-2103

    Last Modified: 16 Apr 2026

    Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an away message with a large number of AIM substitution strings, such as %t or %n.

    Published: 8 Aug 2005
    7.5
    High

    CVE-2005-2483

    Last Modified: 16 Apr 2026

    Eval injection vulnerability in Karrigell before 2.1.8 allows remote attackers to execute arbitrary Python code via modified arguments to a Karrigell services (.ks) script, which can reference functions from libraries that are used by that script.

    Published: 7 Aug 2005
    7.5
    High

    CVE-2005-2484

    Last Modified: 16 Apr 2026

    Buffer overflow in the rdb_query function for Denora IRC Stats 1.0 might allow attackers to execute arbitrary code.

    Published: 7 Aug 2005
    4.3
    Medium

    CVE-2005-2485

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Helpdesk in Logicampus before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 7 Aug 2005
    7.5
    High

    CVE-2005-2489

    Last Modified: 16 Apr 2026

    Web Content Management News System allows remote attackers to create arbitrary accounts and gain privileges via a direct request to Admin/Users/AddModifyInput.php.

    Published: 7 Aug 2005
    4.3
    Medium

    CVE-2005-2488

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Web Content Management News System allows remote attackers to inject arbitrary web script or HTML via (1) the strRootpath parameter to validsession.php or (2) the strTable parameter to Admin/News/List.php.

    Published: 7 Aug 2005
    2.1
    Low

    CVE-2005-2487

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Sun McData switches and directors 4300, 4500, 6064, and 6140 before E/OS 6.0.0 may allow attackers to cause a denial of service (connectivity and array access loss) via a network broadcast storm.

    Published: 7 Aug 2005
    5
    Medium

    CVE-2005-2482

    Last Modified: 16 Apr 2026

    The StateToOptions function in msfweb in Metasploit Framework 2.4 and earlier, when running with the -D option (defanged mode), allows attackers to modify temporary environment variables before the "_Defanged" environment option is checked when processing the Exploit command.

    Published: 7 Aug 2005
    7.5
    High

    CVE-2005-2486

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in mod_forum/read_message.php in PortailPHP allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php with the affiche parameter set to "Forum-read_mess", a different vulnerability than CVE-2005-1701.

    Published: 7 Aug 2005
    4.6
    Medium

    CVE-2005-2555

    Last Modified: 16 Apr 2026

    Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct unauthorized activities via (1) ipv4/ip_sockglue.c and (2) ipv6/ipv6_sockglue.c.

    Published: 6 Aug 2005
    7.5
    High

    CVE-2005-1854

    Last Modified: 16 Apr 2026

    Unknown vulnerability in apt-cacher in Debian 3.1, related to "missing input sanitising," allows remote attackers to execute arbitrary commands on the caching server.

    Published: 5 Aug 2005
    5
    Medium

    CVE-2005-2474

    Last Modified: 16 Apr 2026

    ChurchInfo allows remote attackers to execute obtain sensitive information via the PersonID parameter to (1) PersonView.php, (2) MemberRoleChange.php, (3) PropertyAssign.php, (4) WhyCameEditor.php, (5) GroupPropsEditor.php, (6) Reports/PDFLabel.php, or (7) UserDelete.php, an invalid Number parameter to (8) SelectList.php or (9) SelectDelete.php, GroupID parameter to (10) GroupView.php, (11) GroupMemberList.php, (12) MemberRoleChange.php, (13) GroupDelete.php, (14) /Reports/ClassAttendance.php, or (15) /Reports/GroupReport.php, (16) PropertyID parameter to PropertyEditor.php, FamilyID parameter to (17) Canvas05Editor.php, (18) CanvasEditor.php, or (19) FamilyView.php, or (20) PledgeID parameter to PledgeDetails.php, which reveal the path in an error message.

    Published: 5 Aug 2005
    4.3
    Medium

    CVE-2005-2476

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in lost_passowrd.php in Naxtor Shopping Cart 1.0 allows remote attackers to inject arbitrary web script or HTML via the email parameter.

    Published: 5 Aug 2005
    4.3
    Medium

    CVE-2005-2480

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in ColdFusion Fusebox 4.1.0 allows remote attackers to inject arbitrary web script or HTML via the fuseaction parameter, which is not quoted in an error page, as demonstrated using index.cfm.

    Published: 5 Aug 2005
    5
    Medium

    CVE-2005-2481

    Last Modified: 16 Apr 2026

    ColdFusion Fusebox 4.1.0 allows remote attackers to obtain sensitive information via an invalid fuseaction parameter, which leaks the full server path in an error message, as demonstrated using the "?" (question mark) character.

    Published: 5 Aug 2005
    7.5
    High

    CVE-2005-2473

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in ChurchInfo allow remote attackers to execute arbitrary SQL commands via the PersonID parameter to (1) PersonView.php, (2) MemberRoleChange.php, (3) PropertyAssign.php, (4) WhyCameEditor.php, (5) GroupPropsEditor.php, (6) Reports/PDFLabel.php, or (7) UserDelete.php, (8) DepositSlipID parameter to DepositSlipEditor.php, (9) QueryID parameter to QueryView.php, GroupID parameter to (10) GroupView.php, (11) GroupMemberList.php, (12) MemberRoleChange.php, (13) GroupDelete.php, (14) /Reports/ClassAttendance.php, or (15) /Reports/GroupReport.php, (16) PropertyID parameter to PropertyEditor.php, FamilyID parameter to (17) Canvas05Editor.php, (18) CanvasEditor.php, or (19) FamilyView.php, or (20) PledgeID parameter to PledgeDetails.php.

    Published: 5 Aug 2005
    2.1
    Low

    CVE-2005-2353

    Last Modified: 16 Apr 2026

    run-mozilla.sh in Thunderbird, with debugging enabled, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.

    Published: 5 Aug 2005
    5
    Medium

    CVE-2005-2472

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in BusinessMail 4.60.00 allow remote attackers to cause a denial of service (application crash) via a long string to SMTP (1) HELO or (2) MAIL FROM commands.

    Published: 5 Aug 2005
    7.5
    High

    CVE-2005-2478

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in SilverNews 2.0.3 allows remote attackers to execute arbitrary SQL commands via the user field on the login page in the Admin control panel.

    Published: 5 Aug 2005
    5
    Medium

    CVE-2005-2479

    Last Modified: 16 Apr 2026

    Quick 'n Easy FTP Server 3.0 allows remote attackers to cause a denial of service (application crash or CPU consumption) via a long USER command.

    Published: 5 Aug 2005
    7.5
    High

    CVE-2005-1272

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the Backup Agent for Microsoft SQL Server in BrightStor ARCserve Backup Agent for SQL Server 11.0 allows remote attackers to execute arbitrary code via a long string sent to port (1) 6070 or (2) 6050.

    Published: 5 Aug 2005
    5
    Medium

    CVE-2005-2477

    Last Modified: 16 Apr 2026

    shop_display_products.php in Naxtor Shopping Cart 1.0 allows remote attackers to obtain sensitive information via a cat_id with a "'" (single quote), which reveals the path in an error message, possibly due to an SQL injection vulnerability.

    Published: 5 Aug 2005
    4.9
    Medium

    CVE-2005-4811

    Last Modified: 16 Apr 2026

    The hugepage code (hugetlb.c) in Linux kernel 2.6, possibly 2.6.12 and 2.6.13, in certain configurations, allows local users to cause a denial of service (crash) by triggering an mmap error before a prefault, which causes an error in the unmap_hugepage_area function.

    Published: 5 Aug 2005
    4.3
    Medium

    CVE-2005-2453

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in NetworkActiv Web Server 1.0, 2.0.0.6, 3.0.1.1, and 3.5.13, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the query string.

    Published: 4 Aug 2005
    5
    Medium

    CVE-2005-2455

    Last Modified: 16 Apr 2026

    Greasemonkey before 0.3.5 allows remote web servers to (1) read arbitrary files via a GET request to a file:// URL in the GM_xmlhttpRequest API function, (2) list installed scripts using GM_scripts, or obtain sensitive information via (3) GM_setValue and GM_getValue.

    Published: 4 Aug 2005
    5
    Medium

    CVE-2005-2099

    Last Modified: 16 Apr 2026

    The Linux kernel before 2.6.12.5 does not properly destroy a keyring that is not instantiated properly, which allows local users or remote attackers to cause a denial of service (kernel oops) via a keyring with a payload that is not empty, which causes the creation to fail, leading to a null dereference in the keyring destructor.

    Published: 4 Aug 2005
    5
    Medium

    CVE-2005-2098

    Last Modified: 16 Apr 2026

    The KEYCTL_JOIN_SESSION_KEYRING operation in the Linux kernel before 2.6.12.5 contains an error path that does not properly release the session management semaphore, which allows local users or remote attackers to cause a denial of service (semaphore hang) via a new session keyring (1) with an empty name string, (2) with a long name string, (3) with the key quota reached, or (4) ENOMEM.

    Published: 4 Aug 2005
    10
    Critical

    CVE-2005-2541

    Last Modified: 16 Apr 2026

    Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.

    Published: 4 Aug 2005
    7.2
    High

    CVE-2005-1853

    Last Modified: 16 Apr 2026

    gopher.c in the Gopher client 3.0.5 does not properly create temporary files, which allows local users to gain privileges.

    Published: 3 Aug 2005
    2.1
    Low

    CVE-2005-2132

    Last Modified: 16 Apr 2026

    RPC portmapper (rpcbind) in SCO UnixWare 7.1.1 m5, 7.1.3 mp5, and 7.1.4 mp2 allows remote attackers or local users to cause a denial of service (lack of response) via multiple invalid portmap requests.

    Published: 3 Aug 2005
    5
    Medium

    CVE-2005-2412

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in block.php in PHP FirstPost allows remote attackers to execute arbitrary PHP code via the Include parameter.

    Published: 3 Aug 2005
    4.3
    Medium

    CVE-2005-2416

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module.

    Published: 3 Aug 2005
    5
    Medium

    CVE-2005-2417

    Last Modified: 16 Apr 2026

    Contrexx before 1.0.5 allows remote attackers to obtain sensitive information via a direct request to /config/version.xml.

    Published: 3 Aug 2005
    7.5
    High

    CVE-2005-2419

    Last Modified: 16 Apr 2026

    B-FOCuS Router 312+ allows remote attackers to bypass authentication and gain unauthorized access via a direct request to firmwarecfg.

    Published: 3 Aug 2005
    10
    Critical

    CVE-2005-2420

    Last Modified: 16 Apr 2026

    flsearch.pl in FtpLocate 2.02 allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP GET request.

    Published: 3 Aug 2005
    7.5
    High

    CVE-2005-2421

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in index.php and other pages in Beehive Forum allow remote attackers to execute arbitrary SQL commands via the webtag parameter.

    Published: 3 Aug 2005
    7.5
    High

    CVE-2005-2415

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Contrexx before 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) value parameter to the poll module or (2) pId parameter to the gallery module.

    Published: 3 Aug 2005
    Unknown

    CVE-2005-2418

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-2403. Reason: This candidate is a duplicate of CVE-2005-2403. Notes: All CVE users should reference CVE-2005-2403 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 3 Aug 2005
    10
    Critical

    CVE-2005-2425

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Ares FileShare 1.1 allows remote attackers or local users to execute arbitrary code via a (1) long history parameter in the configuration file (ares.conf) or (2) long search string.

    Published: 3 Aug 2005
    2.1
    Low

    CVE-2005-2426

    Last Modified: 16 Apr 2026

    FTPshell Server 3.38 allows remote authenticated users to cause a denial of service (application crash) by multiple connections and disconnections without using the QUIT command.

    Published: 3 Aug 2005
    4.3
    Medium

    CVE-2005-2427

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter.

    Published: 3 Aug 2005
    5
    Medium

    CVE-2005-2429

    Last Modified: 16 Apr 2026

    Firefox, when opening Microsoft Word documents, does not properly set the permissions on shared sections, which allows remote attackers to write arbitrary data to open applications in Microsoft Office.

    Published: 3 Aug 2005
    5
    Medium

    CVE-2005-2434

    Last Modified: 16 Apr 2026

    Linksys WRT54G router uses the same private key and certificate for every router, which allows remote attackers to sniff the SSL connection and obtain sensitive information.

    Published: 3 Aug 2005
    5
    Medium

    CVE-2005-2436

    Last Modified: 16 Apr 2026

    browse.php in Website Baker Project allows remote attackers to obtain sensitive data via (1) a directory that does not exist in the dir parameter or (2) a direct request to certain php files, which reveal the path in an error message.

    Published: 3 Aug 2005