CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2005-2224

    Last Modified: 16 Apr 2026

    aspnet_wp.exe in Microsoft ASP.NET web services allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a crafted SOAP message to an RPC/Encoded method.

    Published: 12 Jul 2005
    4.6
    Medium

    CVE-2005-2232

    Last Modified: 16 Apr 2026

    Buffer overflow in invscout in IBM AIX 5.1.0 through 5.3.0 might allow local users to execute arbitrary code via a long command line argument.

    Published: 12 Jul 2005
    7.2
    High

    CVE-2005-2235

    Last Modified: 16 Apr 2026

    Buffer overflow in the diagTasksWebSM command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.

    Published: 12 Jul 2005
    7.2
    High

    CVE-2005-2236

    Last Modified: 16 Apr 2026

    Format string vulnerability in the paginit command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via format strings in command line arguments.

    Published: 12 Jul 2005
    5
    Medium

    CVE-2005-2244

    Last Modified: 16 Apr 2026

    The aupair service (aupair.exe) in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to execute arbitrary code or corrupt memory via crafted packets that trigger a memory allocation failure and lead to a buffer overflow.

    Published: 12 Jul 2005
    2.1
    Low

    CVE-2005-2240

    Last Modified: 16 Apr 2026

    xpvm.tcl in xpvm 1.2.5 allows local users to overwrite arbitrary files via a symlink attack on the xpvm.trace.$user temporary file.

    Published: 12 Jul 2005
    7.5
    High

    CVE-2005-0564

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 through 2004, might allow remote attackers to execute arbitrary code via a .doc file with long font information.

    Published: 12 Jul 2005
    7.2
    High

    CVE-2005-2233

    Last Modified: 16 Apr 2026

    Buffer overflow in multiple "p" commands in IBM AIX 5.1, 5.2 and 5.3 might allow local users to execute arbitrary code via long command line arguments to (1) penable or other hard-linked files including (2) pdisable, (3) pstart, (4) phold, (5) pdelay, or (6) pshare.

    Published: 12 Jul 2005
    5
    Medium

    CVE-2005-2241

    Last Modified: 16 Apr 2026

    Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 does not quickly time out Realtime Information Server Data Collection (RISDC) sockets, which results in a "resource leak" that allows remote attackers to cause a denial of service (memory and connection consumption) in RisDC.exe.

    Published: 12 Jul 2005
    5
    Medium

    CVE-2005-2242

    Last Modified: 16 Apr 2026

    Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to cause a denial of service (memory consumption and restart) via crafted packets to (1) the CTI Manager (ctimgr.exe) or (2) the CallManager (ccm.exe).

    Published: 12 Jul 2005
    5
    Medium

    CVE-2005-1174

    Last Modified: 16 Apr 2026

    MIT Kerberos 5 (krb5) 1.3 through 1.4.1 Key Distribution Center (KDC) allows remote attackers to cause a denial of service (application crash) via a certain valid TCP connection that causes a free of unallocated memory.

    Published: 12 Jul 2005
    5
    Medium

    CVE-2005-2263

    Last Modified: 16 Apr 2026

    The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the context of another domain by forcing a page navigation after the install method has been called, which causes the callback to be run in the context of the new page and results in a same origin violation.

    Published: 12 Jul 2005
    7.5
    High

    CVE-2005-1175

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the Key Distribution Center (KDC) in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a certain valid TCP or UDP request.

    Published: 12 Jul 2005
    9.8
    Critical

    CVE-2005-1689

    Last Modified: 16 Apr 2026

    Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.

    Published: 12 Jul 2005
    5
    Medium

    CVE-2005-2265

    Last Modified: 16 Apr 2026

    Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of service (access violation and crash), and possibly execute arbitrary code, by calling InstallVersion.compareTo with an object instead of a string.

    Published: 12 Jul 2005
    7.5
    High

    CVE-2005-2260

    Last Modified: 16 Apr 2026

    The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does not properly distinguish between user-generated events and untrusted synthetic events, which makes it easier for remote attackers to perform dangerous actions that normally could only be performed manually by the user.

    Published: 12 Jul 2005
    7.5
    High

    CVE-2005-2261

    Last Modified: 16 Apr 2026

    Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such protection.

    Published: 12 Jul 2005
    5.1
    Medium

    CVE-2005-2262

    Last Modified: 16 Apr 2026

    Firefox 1.0.3 and 1.0.4, and Netscape 8.0.2, allows remote attackers to execute arbitrary code by tricking the user into using the "Set As Wallpaper" (in Firefox) or "Set as Background" (in Netscape) context menu on an image URL that is really a javascript: URL with an eval statement, aka "Firewalling."

    Published: 12 Jul 2005
    7.5
    High

    CVE-2005-2264

    Last Modified: 16 Apr 2026

    Firefox before 1.0.5 allows remote attackers to steal sensitive information by opening a malicious link in the Firefox sidebar using the _search target, then injecting script into other pages via a data: URL.

    Published: 12 Jul 2005
    7.5
    High

    CVE-2005-2267

    Last Modified: 16 Apr 2026

    Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash and QuickTime to open a javascript: URL, which is run in the context of the previous page, and may lead to code execution if the standalone application loads a privileged chrome: URL.

    Published: 12 Jul 2005
    7.5
    High

    CVE-2005-2269

    Last Modified: 16 Apr 2026

    Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").

    Published: 12 Jul 2005
    5
    Medium

    CVE-2005-2266

    Last Modified: 16 Apr 2026

    Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.

    Published: 12 Jul 2005
    7.5
    High

    CVE-2005-2270

    Last Modified: 16 Apr 2026

    Firefox before 1.0.5 and Mozilla before 1.7.9 does not properly clone base objects, which allows remote attackers to execute arbitrary code by navigating the prototype chain to reach a privileged object.

    Published: 12 Jul 2005
    5
    Medium

    CVE-2005-2170

    Last Modified: 16 Apr 2026

    The LCF component (lcfd) in IBM Tivoli Management Framework Endpoint allows remote attackers to cause a denial of service (process exit and connection loss) by connecting to LCF and ending the connection without sending any data.

    Published: 11 Jul 2005
    7.5
    High

    CVE-2005-2197

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in sql.cls.php in Id Board 1.1.3 allows remote attackers to modify SQL queries, as demonstrated using the f parameter to index.php.

    Published: 11 Jul 2005
    7.5
    High

    CVE-2005-2198

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in lang.php in SPiD before 1.3.1 allows remote attackers to execute arbitrary code via the lang_path parameter.

    Published: 11 Jul 2005
    4.3
    Medium

    CVE-2005-2202

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 11 Jul 2005
    7.5
    High

    CVE-2005-2203

    Last Modified: 16 Apr 2026

    login.php in phpWishlist before 0.1.15 allows remote attackers to bypass authentication via a direct request to admin.php.

    Published: 11 Jul 2005
    4.3
    Medium

    CVE-2005-2204

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Computer Associates (CA) eTrust SiteMinder 5.5, when the "CSSChecking" parameter is set to "NO," allows remote attackers to inject arbitrary web script or HTML via the (1) PASSWORD or (2) BUFFER parameters to smpwservicescgi.exe, (3) the TARGET parameter to login.fcc, and possibly other vectors.

    Published: 11 Jul 2005
    7.5
    High

    CVE-2005-2205

    Last Modified: 16 Apr 2026

    The ReadLog function in kaiseki.cgi in pngren allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.

    Published: 11 Jul 2005
    7.5
    High

    CVE-2005-2206

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in CartWIZ allow remote attackers to modify SQL statements via the (1) idProduct parameter to tellAFriend.asp, (2) sortType parameter to viewSupportTickets.asp, or the id parameter to (3) updateCreditCards.asp or (4) deleteCreditCards.asp.

    Published: 11 Jul 2005
    6.4
    Medium

    CVE-2005-2201

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to cause a denial of service or access files via crafted HTTP requests.

    Published: 11 Jul 2005
    7.5
    High

    CVE-2005-2210

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Internet Download Manager 4.05 allows remote attackers to execute arbitrary code via a long URL.

    Published: 11 Jul 2005
    4.6
    Medium

    CVE-2005-2211

    Last Modified: 16 Apr 2026

    Backup Manager 0.5.8a creates temporary files insecurely, which allows local users to conduct unauthorized file operations when a user is burning a CDR.

    Published: 11 Jul 2005
    6.4
    Medium

    CVE-2005-2212

    Last Modified: 16 Apr 2026

    Backup Manager 0.5.8a creates an archive repository with world readable and writable permissions, which allows attackers to modify or read the repository.

    Published: 11 Jul 2005
    7.5
    High

    CVE-2005-2213

    Last Modified: 16 Apr 2026

    Buffer overflow in the mms_interp_header function in mms.c in MMS Ripper before 0.6.4 might allow remote attackers to execute arbitrary code via a file with more than 20 streams.

    Published: 11 Jul 2005
    4.6
    Medium

    CVE-2005-2214

    Last Modified: 16 Apr 2026

    apt-setup in Debian GNU/Linux installs the apt.conf file with insecure permissions, which allows local users to obtain sensitive information such as passwords.

    Published: 11 Jul 2005
    4.3
    Medium

    CVE-2005-2207

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in store/login.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter.

    Published: 11 Jul 2005
    5
    Medium

    CVE-2005-2150

    Last Modified: 16 Apr 2026

    Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which allows remote attackers to (1) list Windows services via svcctl or (2) read eventlogs via eventlog.

    Published: 11 Jul 2005
    7.5
    High

    CVE-2005-2199

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in inc/functions.inc.php in PPA web photo gallery 0.5.6 allows remote attackers to execute arbitrary code via the config[ppa_root_path] variable.

    Published: 11 Jul 2005
    7.5
    High

    CVE-2005-2200

    Last Modified: 16 Apr 2026

    Multiple unknown vulnerabilities in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to bypass authentication.

    Published: 11 Jul 2005
    5
    Medium

    CVE-2005-2208

    Last Modified: 16 Apr 2026

    PrivaShare 1.1b allows remote attackers to cause a denial of service (crash) via a malformed message.

    Published: 11 Jul 2005
    5.5
    Medium

    CVE-2005-2209

    Last Modified: 16 Apr 2026

    Capturix ScanShare 1.06 build 50 stores sensitive information such as the password in cleartext in capturixss_cfg.ini, which is readable by local users.

    Published: 11 Jul 2005
    5
    Medium

    CVE-2005-1848

    Last Modified: 16 Apr 2026

    The dhcpcd DHCP client before 1.3.22 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors that cause an out-of-bounds memory read.

    Published: 11 Jul 2005
    7.5
    High

    CVE-2005-2181

    Last Modified: 16 Apr 2026

    Cisco 7940/7960 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message.

    Published: 10 Jul 2005
    7.5
    High

    CVE-2005-2182

    Last Modified: 16 Apr 2026

    Grandstream BudgeTone (BT) 100 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message.

    Published: 10 Jul 2005
    7.5
    High

    CVE-2005-2183

    Last Modified: 16 Apr 2026

    class.xmail.php in PhpXmail 0.7 through 1.1 does not properly handle large passwords, which prevents an error message from being returned and allows remote attackers to bypass authentication and gain unauthorized access.

    Published: 10 Jul 2005
    7.5
    High

    CVE-2005-2184

    Last Modified: 16 Apr 2026

    eRoom 6.x does not properly restrict files that can be attached, which allows remote attackers to execute arbitrary commands via a .lnk file.

    Published: 10 Jul 2005
    5
    Medium

    CVE-2005-2189

    Last Modified: 16 Apr 2026

    Lantronix SecureLinx console server running firmware 2.0 and 3.0 stores /etc/ssh under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as SSH private keys.

    Published: 10 Jul 2005
    7.5
    High

    CVE-2005-2190

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Comersus shopping cart allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to comersus_optAffiliateRegistrationExec.asp or (2) idProduct parameter to comersus_optReviewReadExec.asp.

    Published: 10 Jul 2005