CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2005-2135

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in verify.asp in EtoShop Dynamic Biz Website Builder (QuickWeb) 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) T1 or (2) T2 parameters.

    Published: 5 Jul 2005
    4.6
    Medium

    CVE-2005-2136

    Last Modified: 16 Apr 2026

    Raritan Dominion SX (DSX) Console Servers DSX16, DSX32, DSX4, DSX8, and DSXA-48 set (1) world-readable permissions for /etc/shadow and (2) world-writable permissions for /bin/busybox, which allows local users to obtain hashed passwords or execute arbitrary code as other users.

    Published: 5 Jul 2005
    5
    Medium

    CVE-2005-2141

    Last Modified: 16 Apr 2026

    TCP Chat 1.0 allows remote attackers to cause a denial of service (crash) via a long string to the chat service, possibly triggering a buffer overflow.

    Published: 5 Jul 2005
    2.1
    Low

    CVE-2005-2142

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Golden FTP Server 2.60 allows remote authenticated attackers to list arbitrary directories via a "\.." (backslash dot dot) in an LS (LIST) command.

    Published: 5 Jul 2005
    4.6
    Medium

    CVE-2005-2145

    Last Modified: 16 Apr 2026

    The kernel driver in Prevx Pro 2005 1.0 does not verify the source of certain messages, which allows local users to bypass protection by sending certain messages to the driver, as demonstrated by sending an "allow" message to bypass a warning message.

    Published: 5 Jul 2005
    5
    Medium

    CVE-2005-1625

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the UnixAppOpenFilePerform function in Adobe Reader 5.0.9 and 5.0.10 for Unix allows remote attackers to execute arbitrary code via a PDF document with a long /Filespec tag.

    Published: 5 Jul 2005
    2.1
    Low

    CVE-2005-2134

    Last Modified: 16 Apr 2026

    The (1) clcs and (2) emuxki drivers in NetBSD 1.6 through 2.0.2 allow local users to cause a denial of service (kernel crash) by using the set-parameters ioctl on an audio device to change the block size and set the pause state to "unpaused" in the same ioctl, which causes a divide-by-zero error.

    Published: 5 Jul 2005
    3.7
    Low

    CVE-2005-1768

    Last Modified: 16 Apr 2026

    Race condition in the ia32 compatibility code for the execve system call in Linux kernel 2.4 before 2.4.31 and 2.6 before 2.6.6 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via a concurrent thread that increments a pointer count after the nargs function has counted the pointers, but before the count is copied from user space to kernel space, which leads to a buffer overflow.

    Published: 4 Jul 2005
    5
    Medium

    CVE-2005-2109

    Last Modified: 16 Apr 2026

    wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use.

    Published: 1 Jul 2005
    7.5
    High

    CVE-2005-2111

    Last Modified: 16 Apr 2026

    login.cgi in Community Link Pro Web Editor allows remote attackers to execute arbitrary commands via the file parameter.

    Published: 1 Jul 2005
    4.3
    Medium

    CVE-2005-2112

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) order parameter to edit.php or (2) cid parameter to comment_edit.php.

    Published: 1 Jul 2005
    4.3
    Medium

    CVE-2005-2107

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p or (2) comment parameter.

    Published: 1 Jul 2005
    Unknown

    CVE-2005-2116

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-1921. Reason: This candidate is a duplicate of CVE-2005-1921. Notes: All CVE users should reference CVE-2005-1921 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 1 Jul 2005
    5
    Medium

    CVE-2005-2106

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or posting.

    Published: 1 Jul 2005
    5
    Medium

    CVE-2005-2115

    Last Modified: 16 Apr 2026

    Soldier of Fortune II 1.02x and 1.03 allows remote attackers to cause a denial of service (server crash) via a large ID value in the ignore command, which is used as an array index and causes an out-of-bounds operation.

    Published: 1 Jul 2005
    5
    Medium

    CVE-2005-0360

    Last Modified: 16 Apr 2026

    The Microsoft Log Sink Class ActiveX control in pkmcore.dll is marked as "safe for scripting" for Internet Explorer, which allows remote attackers to create or append to arbitrary files.

    Published: 1 Jul 2005
    7.2
    High

    CVE-2005-0393

    Last Modified: 16 Apr 2026

    The helper scripts for crip 3.5 do not properly use temporary files, which allows local users to have an unknown impact with unknown attack vectors.

    Published: 1 Jul 2005
    7.5
    High

    CVE-2005-2113

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via crafted values in an XML file, as demonstrated using the blogger.getPost method.

    Published: 1 Jul 2005
    7.5
    High

    CVE-2005-2105

    Last Modified: 16 Apr 2026

    Cisco IOS 12.2T through 12.4 allows remote attackers to bypass Authentication, Authorization, and Accounting (AAA) RADIUS authentication, if the fallback method is set to none, via a long username.

    Published: 1 Jul 2005
    7.5
    High

    CVE-2005-2108

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that is not filtered in the HTTP_RAW_POST_DATA variable, which stores the data in an XML file.

    Published: 1 Jul 2005
    5
    Medium

    CVE-2005-2110

    Last Modified: 16 Apr 2026

    WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-header.php or a "1" value in the feed parameter to (2) wp-atom.php, (3) wp-rss.php, or (4) wp-rss2.php, which reveal the path in an error message. NOTE: vector [1] was later reported to also affect WordPress 2.0.1.

    Published: 1 Jul 2005
    5
    Medium

    CVE-2005-2177

    Last Modified: 16 Apr 2026

    Net-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when net-snmp is using stream sockets such as TCP, allows remote attackers to cause a denial of service (daemon hang and CPU consumption) via a TCP packet of length 1, which triggers an infinite loop.

    Published: 1 Jul 2005
    2.6
    Low

    CVE-2005-1923

    Last Modified: 16 Apr 2026

    The ENSURE_BITS macro in mszipd.c for Clam AntiVirus (ClamAV) 0.83, and other versions vefore 0.86, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a cabinet (CAB) file with the cffile_FolderOffset field set to 0xff, which causes a zero-length read.

    Published: 30 Jun 2005
    5
    Medium

    CVE-2005-2068

    Last Modified: 16 Apr 2026

    FreeBSD 4.x through 4.11 and 5.x through 5.4 allows remote attackers to modify certain TCP options via a TCP packet with the SYN flag set for an already established session.

    Published: 30 Jun 2005
    4.3
    Medium

    CVE-2005-2084

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in SearchResults.aspx in Community Forum allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Published: 30 Jun 2005
    5
    Medium

    CVE-2005-2085

    Last Modified: 16 Apr 2026

    Buffer overflow in Inframail Advantage Server Edition 6.0 through 6.7 allows remote attackers to cause a denial of service (process crash) via a long (1) SMTP FROM field or possibly (2) FTP NLST command.

    Published: 30 Jun 2005
    7.5
    High

    CVE-2005-2086

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute arbitrary PHP code.

    Published: 30 Jun 2005
    4.3
    Medium

    CVE-2005-2092

    Last Modified: 16 Apr 2026

    BEA Systems WebLogic 8.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes WebLogic to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."

    Published: 30 Jun 2005
    5
    Medium

    CVE-2005-1931

    Last Modified: 16 Apr 2026

    GoodTech SMTP Server 5.14 allows remote attackers to cause a denial of service (application crash) via a RCPT TO command with an invalid argument, as demonstrated using an "A" character.

    Published: 30 Jun 2005
    5
    Medium

    CVE-2005-2019

    Last Modified: 16 Apr 2026

    ipfw in FreeBSD 5.4, when running on Symmetric Multi-Processor (SMP) or Uni Processor (UP) systems with the PREEMPTION kernel option enabled, does not sufficiently lock certain resources while performing table lookups, which can cause the cache results to be corrupted during multiple concurrent lookups, allowing remote attackers to bypass intended access restrictions.

    Published: 30 Jun 2005
    5
    Medium

    CVE-2005-2087

    Last Modified: 16 Apr 2026

    Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, as demonstrated using the JVIEW Profiler (Javaprxy.dll). NOTE: the researcher says that the vendor could not reproduce this problem.

    Published: 30 Jun 2005
    4.3
    Medium

    CVE-2005-2089

    Last Modified: 16 Apr 2026

    Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes IIS to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."

    Published: 30 Jun 2005
    5
    Medium

    CVE-2005-1922

    Last Modified: 16 Apr 2026

    The MS-Expand file handling in Clam AntiVirus (ClamAV) before 0.86 allows remote attackers to cause a denial of service (file descriptor and memory consumption) via a crafted file that causes repeated errors in the cli_msexpand function.

    Published: 30 Jun 2005
    2.1
    Low

    CVE-2005-1932

    Last Modified: 16 Apr 2026

    Lpanel 1.59 and earlier, and other versions before 1.597, allows remote authenticated users to modify certain critical variables and (1) modify DNS settings for arbitrary domains via the domain parameter to diagnose.php, (2) close, open, or respond to arbitrary support tickets via the close, open, or pid parameter to view_ticket.php, (3) obtain sensitive information on arbitrary invoices via the inv parameter to viewreceipt.php, or (4) modify domain information for arbitrary domains via the editdomain parameter to domains.php.

    Published: 30 Jun 2005
    5
    Medium

    CVE-2005-2081

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the function that parses commands in Asterisk 1.0.7, when the 'write = command' option is enabled, allows remote attackers to execute arbitrary code via a command that has two double quotes followed by a tab character.

    Published: 30 Jun 2005
    5
    Medium

    CVE-2005-2082

    Last Modified: 16 Apr 2026

    im_trbbs.cgi in imTRSET 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the df parameter.

    Published: 30 Jun 2005
    5
    Medium

    CVE-2005-2083

    Last Modified: 16 Apr 2026

    Format string vulnerability in IMAP4 in IA eMailServer Corporate Edition 5.2.2 build 1051 allows remote attackers to cause a denial of service (application crash) via a LIST command with format string specifiers as the second argument.

    Published: 30 Jun 2005
    4.3
    Medium

    CVE-2005-2091

    Last Modified: 16 Apr 2026

    IBM WebSphere 5.1 and WebSphere 5.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes WebSphere to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."

    Published: 30 Jun 2005
    4.3
    Medium

    CVE-2005-2094

    Last Modified: 16 Apr 2026

    Sun SunONE web server 6.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes SunONE to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."

    Published: 30 Jun 2005
    4.3
    Medium

    CVE-2005-2093

    Last Modified: 16 Apr 2026

    Oracle 9i Application Server (Oracle9iAS) 9.0.2 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Application Server to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."

    Published: 30 Jun 2005
    2.1
    Low

    CVE-2005-1767

    Last Modified: 16 Apr 2026

    traps.c in the Linux kernel 2.6.x and 2.4.x executes stack segment faults on an exception stack, which allows local users to cause a denial of service (oops and stack fault exception).

    Published: 30 Jun 2005
    5
    Medium

    CVE-2006-1931

    Last Modified: 16 Apr 2026

    The HTTP/XMLRPC server in Ruby before 1.8.2 uses blocking sockets, which allows attackers to cause a denial of service (blocked connections) via a large amount of data.

    Published: 30 Jun 2005
    Unknown

    CVE-2005-1938

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-1250. Reason: This candidate is a duplicate of CVE-2005-1250. Notes: this duplicate occurred as a result of multiple independent discoveries and insufficient coordination by the vendor and CNA. All CVE users should reference CVE-2005-1250 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 29 Jun 2005
    5
    Medium

    CVE-2005-2070

    Last Modified: 16 Apr 2026

    The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a denial of service by keeping an open connection, which prevents ClamAV from reloading.

    Published: 29 Jun 2005
    2.1
    Low

    CVE-2005-2073

    Last Modified: 16 Apr 2026

    Unknown vulnerability in IBM DB2 8.1.4 through 8.1.9 and 8.2.0 through 8.2.2 allows local users with SELECT privileges to conduct unauthorized activities and insert, update or delete table contents.

    Published: 29 Jun 2005
    5
    Medium

    CVE-2005-2075

    Last Modified: 16 Apr 2026

    PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to the filename in the administration/db_backups directory in PHP-Fusion 6.0 or the fusion_admin/db_backups directory in 5.0.

    Published: 29 Jun 2005
    2.1
    Low

    CVE-2005-2076

    Last Modified: 16 Apr 2026

    HP Version Control Repository Manager (VCRM) before 2.1.1.730 does not properly handle the "@" character in a proxy password, which could allow attackers with physical access to obtain portions of the password when it is displayed to the screen.

    Published: 29 Jun 2005
    4.3
    Medium

    CVE-2005-2077

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in error.asp for Hosting Controller allows remote attackers to inject arbitrary web script or HTML via the error parameter.

    Published: 29 Jun 2005
    2.1
    Low

    CVE-2005-2078

    Last Modified: 16 Apr 2026

    BisonFTP Server V4R1 allows remote authenticated users to cause a denial of service via an invalid command with a long argument.

    Published: 29 Jun 2005
    Unknown

    CVE-2005-1690

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-1250. Reason: This candidate is a duplicate of CVE-2005-1250. Notes: this duplicate occurred as a result of multiple independent discoveries and insufficient coordination by the vendor and CNA. All CVE users should reference CVE-2005-1250 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 29 Jun 2005