CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2005-2440

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in login.asp in Thomson Web Skill Vantage Manager allows remote attackers to execute arbitrary SQL commands via the svmPassword parameter.

    Published: 3 Aug 2005
    4.3
    Medium

    CVE-2005-2441

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in VBzoom allow remote attackers to inject arbitrary web script and HTML via the (1) UserName parameter to profile.php or (2) UserID parameter to login.php.

    Published: 3 Aug 2005
    5
    Medium

    CVE-2005-2442

    Last Modified: 16 Apr 2026

    Cross-Application Scripting (XAS) vulnerability in SPI Dynamics WebInspect 5.0.196 allows remote attackers to inject Javascript from one application into another.

    Published: 3 Aug 2005
    5
    Medium

    CVE-2005-2443

    Last Modified: 16 Apr 2026

    Kshout 2.x and 3.x stores settings.dat under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and passwords.

    Published: 3 Aug 2005
    2.1
    Low

    CVE-2005-2444

    Last Modified: 16 Apr 2026

    Trillian Pro 3.1 build 121, when checking Yahoo e-mail, stores the password in plaintext in a world readable file and does not delete the file after login, which allows local users to obtain sensitive information.

    Published: 3 Aug 2005
    7.5
    High

    CVE-2005-2445

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in viewPrd.asp in Product Cart 2.6 allows remote attackers to execute arbitrary SQL commands via the idcategory parameter.

    Published: 3 Aug 2005
    1.2
    Low

    CVE-2005-2449

    Last Modified: 16 Apr 2026

    Race condition in sandbox before 1.2.11 allows local users to create or overwrite arbitrary files via symlink attack on sandboxpids.tmp.

    Published: 3 Aug 2005
    7.5
    High

    CVE-2005-2450

    Last Modified: 16 Apr 2026

    Multiple integer overflows in the (1) TNEF, (2) CHM, or (3) FSG file format processors in libclamav for Clam AntiVirus (ClamAV) 0.86.1 and earlier allow remote attackers to gain privileges via a crafted e-mail message.

    Published: 3 Aug 2005
    2.1
    Low

    CVE-2005-2451

    Last Modified: 16 Apr 2026

    Cisco IOS 12.0 through 12.4 and IOS XR before 3.2, with IPv6 enabled, allows remote attackers on a local network segment to cause a denial of service (device reload) and possibly execute arbitrary code via a crafted IPv6 packet.

    Published: 3 Aug 2005
    7.5
    High

    CVE-2005-2346

    Last Modified: 16 Apr 2026

    Buffer overflow in Novell GroupWise 6.5 Client allows remote attackers to execute arbitrary code via a GWVW02xx.INI language file with a long entry, as demonstrated using a long ES02TKS.VEW value in the Group Task section.

    Published: 3 Aug 2005
    5
    Medium

    CVE-2005-2423

    Last Modified: 16 Apr 2026

    Beehive Forum allows remote attackers to obtain sensitive information via (1) an invalid final_uri or sort_by parameter to index.php or a direct request to (2) admin.php, (3) attachments.inc.php, (4) banned.inc.php, (5) beehive.inc.php, (6) constants.inc.php, (7) db.inc.php, (8) dictionary.inc.php or (9) search_index.php, which reveal the path in an error message.

    Published: 3 Aug 2005
    5
    Medium

    CVE-2005-2431

    Last Modified: 16 Apr 2026

    The (1) lost password and (2) account pending features in GForge 4.5 do not properly set a limit on the number of e-mails sent to an e-mail address, which allows remote attackers to send a large number of messages to arbitrary e-mail addresses (aka mail bomb).

    Published: 3 Aug 2005
    4.3
    Medium

    CVE-2005-2435

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in browse.php in Website Baker Project allows remote attackers to inject arbitrary web script or HTML via the dir parameter.

    Published: 3 Aug 2005
    4.3
    Medium

    CVE-2005-2438

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in UseBB 0.5.1 and earlier allows remote attackers to inject arbitrary Javascript via the BBCode color value.

    Published: 3 Aug 2005
    Unknown

    CVE-2005-2447

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-2370. Reason: This candidate is a duplicate of CVE-2005-2370. Notes: All CVE users should reference CVE-2005-2370 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 3 Aug 2005
    2.6
    Low

    CVE-2005-2414

    Last Modified: 16 Apr 2026

    Race condition in the xpcom library, as used by web browsers such as Firefox, Mozilla, Netscape, and Galeon, allows remote attackers to cause a denial of service (application crash) via a large HTML file that loads a DOM call from within nested DIV tags, which causes part of the currently rendering page and referenced objects to be deleted.

    Published: 3 Aug 2005
    7.5
    High

    CVE-2005-2424

    Last Modified: 16 Apr 2026

    The management interface for Siemens SANTIS 50 running firmware 4.2.8.0, and possibly other products including Ericsson HN294dp and Dynalink RTA300W, allows remote attackers to access the Telnet port without authentication via certain packets to the web interface that cause the interface to freeze.

    Published: 3 Aug 2005
    5
    Medium

    CVE-2005-2428

    Last Modified: 16 Apr 2026

    Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client platform in the ClntPltfrm field, (4) the client machine name in the ClntMachine field, and (5) the client Lotus Domino release in the ClntBld field, a different vulnerability than CVE-2005-2696.

    Published: 3 Aug 2005
    4.3
    Medium

    CVE-2005-2430

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id or (2) group_id parameter to forum.php, (3) project_task_id parameter to task.php, (4) id parameter to detail.php, (5) the text field on the search page, (6) group_id parameter to qrs.php, (7) form, (8) rows, (9) cols or (10) wrap parameter to notepad.php, or the login field on the login form.

    Published: 3 Aug 2005
    7.5
    High

    CVE-2005-2432

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in PhpList allows remote attackers to modify SQL statements via the id argument to admin pages such as (1) members or (2) admin.

    Published: 3 Aug 2005
    5
    Medium

    CVE-2005-2433

    Last Modified: 16 Apr 2026

    PhpList allows remote attackers to obtain sensitive information via a direct request to (1) about.php, (2) connect.php, (3) domainstats.php or (4) usercheck.php in public_html/lists/admin directory, (5) attributes.php, (6) dbcheck.php, (7) importcsv.php, (8) user.php, (9) usermgt.php, or (10) users.php in admin/commonlib/pages directory, (11) helloworld.php, or (12) sidebar.php in public_html/lists/admin/plugins directory, or (13) main.php in public_html/lists/admin/plugsins/defaultplugin directory, which reveal the path in an error message.

    Published: 3 Aug 2005
    7.5
    High

    CVE-2005-2439

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in UseBB 0.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search function.

    Published: 3 Aug 2005
    5
    Medium

    CVE-2005-2452

    Last Modified: 16 Apr 2026

    libtiff up to 3.7.0 allows remote attackers to cause a denial of service (application crash) via a TIFF image header with a zero "YCbCr subsampling" value, which causes a divide-by-zero error in (1) tif_strip.c and (2) tif_tile.c, a different vulnerability than CVE-2004-0804.

    Published: 3 Aug 2005
    Unknown

    CVE-2005-2446

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-2369. Reason: This candidate is a duplicate of CVE-2005-2369. Notes: All CVE users should reference CVE-2005-2369 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 3 Aug 2005
    5
    Medium

    CVE-2005-2413

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in apa_phpinclude.inc.php in Atomic Photo Album (APA) allows remote attackers to execute arbitrary PHP code via the apa_module_basedir parameter.

    Published: 3 Aug 2005
    4.3
    Medium

    CVE-2005-2422

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Beehive Forum allows remote attackers to inject arbitrary web script or HTML via the webtag parameter.

    Published: 3 Aug 2005
    5
    Medium

    CVE-2005-2437

    Last Modified: 16 Apr 2026

    Website Baker Project does not properly verify the file extensions of uploaded files, which allows remote attackers to upload and execute arbitrary PHP code.

    Published: 3 Aug 2005
    1.2
    Low

    CVE-2005-2475

    Last Modified: 16 Apr 2026

    Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by Unzip after the decompression is complete.

    Published: 2 Aug 2005
    7.5
    High

    CVE-2005-2409

    Last Modified: 16 Apr 2026

    Format string vulnerability in util.c in nbsmtp 0.99 and earlier, while running in debug mode, allows remote attackers to execute arbitrary code via format string specifiers that are not properly handled in a syslog call.

    Published: 1 Aug 2005
    7.5
    High

    CVE-2005-2410

    Last Modified: 16 Apr 2026

    Format string vulnerability in the nm_info_handler function in Network Manager may allow remote attackers to execute arbitrary code via format string specifiers in a Wireless Access Point identifier, which is not properly handled in a syslog call.

    Published: 1 Aug 2005
    5.1
    Medium

    CVE-2005-2411

    Last Modified: 16 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in tDiary 2.1.1, and tDiary 2.0.1 and earlier, allows remote attackers to conduct actions as another user, and execute commands on the server, via a URL that is activated by the user.

    Published: 1 Aug 2005
    5
    Medium

    CVE-2005-2359

    Last Modified: 16 Apr 2026

    The AES-XCBC-MAC algorithm in IPsec in FreeBSD 5.3 and 5.4, when used for authentication without other encryption, uses a constant key instead of the one that was assigned by the system administrator, which can allow remote attackers to spoof packets to establish an IPsec session.

    Published: 1 Aug 2005
    7.5
    High

    CVE-2005-2491

    Last Modified: 16 Apr 2026

    Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.

    Published: 1 Aug 2005
    2.1
    Low

    CVE-2005-3053

    Last Modified: 16 Apr 2026

    The sys_set_mempolicy function in mempolicy.c in Linux kernel 2.6.x allows local users to cause a denial of service (kernel BUG()) via a negative first argument.

    Published: 1 Aug 2005
    5.1
    Medium

    CVE-2005-2407

    Last Modified: 16 Apr 2026

    A design error in Opera 8.01 and earlier allows user-assisted attackers to execute arbitrary code by overlaying a malicious new window above a file download dialog box, then tricking the user into double-clicking on the "Run" button, aka "link hijacking".

    Published: 28 Jul 2005
    5
    Medium

    CVE-2005-2405

    Last Modified: 16 Apr 2026

    Opera 8.01, when the "Arial Unicode MS" font (ARIALUNI.TTF) is installed, does not properly handle extended ASCII characters in the file download dialog box, which allows remote attackers to spoof file extensions and possibly trick users into executing arbitrary code.

    Published: 28 Jul 2005
    4.3
    Medium

    CVE-2005-2406

    Last Modified: 16 Apr 2026

    Opera 8.01 allows remote attackers to conduct cross-site scripting (XSS) attacks or modify which files are uploaded by tricking a user into dragging an image that is a "javascript:" URI.

    Published: 28 Jul 2005
    7.5
    High

    CVE-2005-2385

    Last Modified: 16 Apr 2026

    Buffer overflow in a third-party compression library (UNACEV2.DLL), as used in avast! Antivirus Home/Professional Edition 4.6.665 and Server Edition 4.6.460, allows remote attackers to execute arbitrary code via an ACE archive containing a long filename.

    Published: 27 Jul 2005
    4.3
    Medium

    CVE-2005-2386

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ 1.20 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

    Published: 27 Jul 2005
    6.4
    Medium

    CVE-2005-2390

    Last Modified: 16 Apr 2026

    Multiple format string vulnerabilities in ProFTPD before 1.3.0rc2 allow attackers to cause a denial of service or obtain sensitive information via (1) certain inputs to the shutdown message from ftpshut, or (2) the SQLShowInfo mod_sql directive.

    Published: 27 Jul 2005
    5
    Medium

    CVE-2005-2391

    Last Modified: 16 Apr 2026

    Unknown vulnerability in 3Com OfficeConnect Wireless 11g Access Point before 1.03.12 allows remote attackers to obtain sensitive information via the web interface.

    Published: 27 Jul 2005
    4.3
    Medium

    CVE-2005-2392

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php for CMSimple 2.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in the search function.

    Published: 27 Jul 2005
    4.3
    Medium

    CVE-2005-2393

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in CuteNews 1.3.6 allows remote attackers to inject arbitrary web script or HTML via (1) the lastusername parameter to index.php or (2) selected_search_arch parameter to search.php.

    Published: 27 Jul 2005
    5
    Medium

    CVE-2005-2394

    Last Modified: 16 Apr 2026

    show_news.php in CuteNews 1.3.6 allows remote attackers to obtain the full path of the server via an invalid archive parameter.

    Published: 27 Jul 2005
    5
    Medium

    CVE-2005-2389

    Last Modified: 16 Apr 2026

    NDMP server in Veritas NetBackup 5.1 allows attackers to cause a denial of service via a CONFIG message with an out-of-range timestamp, which triggers a null dereference.

    Published: 27 Jul 2005
    7.5
    High

    CVE-2005-2399

    Last Modified: 16 Apr 2026

    PHP Surveyor 0.98 allows remote attackers to trigger SQL errors via missing parameters to (1) browse.php, (2) export.php, (3) conditions.php, or (4) spss.php.

    Published: 27 Jul 2005
    7.5
    High

    CVE-2005-2400

    Last Modified: 16 Apr 2026

    The inc.login.php scripts in PHPFinance 0.3 allows remote attackers to bypass the login and gain privileges.

    Published: 27 Jul 2005
    5
    Medium

    CVE-2005-2401

    Last Modified: 16 Apr 2026

    PHP-Fusion allows remote attackers to inject arbitrary Cascading Style Sheets (CSS) via the BBCode color tag.

    Published: 27 Jul 2005
    4.3
    Medium

    CVE-2005-2402

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in PHPSiteSearch 1.7.7d allows remote attackers to inject arbitrary web script or HTML via the query parameter.

    Published: 27 Jul 2005
    5
    Medium

    CVE-2005-2403

    Last Modified: 16 Apr 2026

    The login protocol in RealChat 3.5.1b does not use authentication, which allows remote attackers to log on as other users by sniffing the beginning of a chat session and replaying it via a modified username.

    Published: 27 Jul 2005