CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2005-2034

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in folderview.asp for BlueCollar iGallery 3.3 allows remote attackers to inject arbitrary web script or HTML via the folder parameter.

    Published: 20 Jun 2005
    5
    Medium

    CVE-2005-2038

    Last Modified: 16 Apr 2026

    Fortibus CMS 4.0.0 allows remote attackers to modify information of other users, including Admin, via the "My info" page.

    Published: 20 Jun 2005
    4.3
    Medium

    CVE-2005-2011

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in paFAQ 1.0 Beta 4 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the id parameter in a Question action.

    Published: 20 Jun 2005
    7.5
    High

    CVE-2005-2012

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in login in paFAQ 1.0 Beta 4 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) id parameters.

    Published: 20 Jun 2005
    4.3
    Medium

    CVE-2005-2021

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in cPanel 9.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the user parameter in the login page.

    Published: 20 Jun 2005
    5
    Medium

    CVE-2005-2025

    Last Modified: 16 Apr 2026

    Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the groupname in the ID field, which generates a response if the groupname is valid, but does not generate a response for an invalid groupname.

    Published: 20 Jun 2005
    5
    Medium

    CVE-2005-2040

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the getterminaltype function in telnetd for Heimdal before 0.6.5 may allow remote attackers to execute arbitrary code, a different vulnerability than CVE-2005-0468 and CVE-2005-0469.

    Published: 20 Jun 2005
    4.3
    Medium

    CVE-2005-2010

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in trackback.asp in Ublog Reload 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the btitle parameter.

    Published: 20 Jun 2005
    3.7
    Low

    CVE-2005-1993

    Last Modified: 16 Apr 2026

    Race condition in sudo 1.3.1 up to 1.6.8p8, when the ALL pseudo-command is used after a user entry in the sudoers file, allows local users to gain privileges via a symlink attack.

    Published: 20 Jun 2005
    6.4
    Medium

    CVE-2005-2007

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Edgewall Trac 0.8.3 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the id parameter to the (1) upload or (2) attachment scripts.

    Published: 19 Jun 2005
    5
    Medium

    CVE-2005-2039

    Last Modified: 16 Apr 2026

    Unknown vulnerability in "various plugins" for NanoBlogger 3.2.1 and earlier allows remote attackers to execute arbitrary commands.

    Published: 19 Jun 2005
    7.5
    High

    CVE-2005-0773

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in VERITAS Backup Exec Remote Agent 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for Netware allows remote attackers to execute arbitrary code via a CONNECT_CLIENT_AUTH request with authentication method type 3 (Windows credentials) and a long password argument.

    Published: 18 Jun 2005
    5
    Medium

    CVE-2005-2008

    Last Modified: 16 Apr 2026

    Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trailing %00 (null).

    Published: 17 Jun 2005
    7.5
    High

    CVE-2005-2029

    Last Modified: 16 Apr 2026

    amaroK Web Frontend 1.3 stores the globals.inc file under the web root without a .php extension and insufficient access control, which allows remote attackers to obtain the database username and password via a direct request to the file.

    Published: 17 Jun 2005
    5
    Medium

    CVE-2005-2043

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in XAMPP before 1.4.14 allows remote attackers to inject arbitrary HTML and PHP code via lang.php.

    Published: 17 Jun 2005
    5
    Medium

    CVE-2005-2004

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting vulnerabilities in Ultimate PHP Board (UPB) 1.9.6 GOLD and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ref parameter to login.php, (2) id or (3) page parameter to viewtopic.php, id parameter to (4) profile.php, (5) newpost.php, (6) email.php, (7) icq.php, or (8) aol.php, (9) t_id parameter to newpost.php, (10) ref parameter to getpass.php, or (11) sText parameter to search.php.

    Published: 17 Jun 2005
    10
    Critical

    CVE-2005-2023

    Last Modified: 16 Apr 2026

    The send_pinentry_environment function in asshelp.c in gpg2 on SUSE Linux 9.3 does not properly handle certain options, which can prevent pinentry from being found and causes S/MIME signing to fail.

    Published: 17 Jun 2005
    5
    Medium

    CVE-2005-2006

    Last Modified: 16 Apr 2026

    JBOSS 3.2.2 through 3.2.7 and 4.0.2 allows remote attackers to obtain sensitive information via a GET request (1) with a "%." (percent dot), which reveals the installation path or (2) with a % (percent) before a filename, which reveals the contents of the file.

    Published: 17 Jun 2005
    4.3
    Medium

    CVE-2005-2022

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Webmail in iPlanet Messaging Server 5.2 Patch 1 and Sun ONE Messaging Server 6.2 allows remote attackers to execute arbitrary Javascript, possibly due to a cross-site scripting (XSS) vulnerability.

    Published: 17 Jun 2005
    5
    Medium

    CVE-2005-2024

    Last Modified: 16 Apr 2026

    Vipul Razor Agents (razor-agents) before 2.70 allows remote attackers to cause a denial of service via (1) certain "unusual HTML messages" or (2) "certain malformed headers" such as Content-Type.

    Published: 17 Jun 2005
    5.1
    Medium

    CVE-2006-0300

    Last Modified: 16 Apr 2026

    Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.

    Published: 17 Jun 2005
    7.5
    High

    CVE-2005-1992

    Last Modified: 16 Apr 2026

    The XMLRPC server in utils.rb for the ruby library (libruby) 1.8 sets an invalid default value that prevents "security protection" using handlers, which allows remote attackers to execute arbitrary commands.

    Published: 17 Jun 2005
    7.5
    High

    CVE-2005-1475

    Last Modified: 16 Apr 2026

    The XMLHttpRequest object in Opera 8.0 Final Build 1095 allows remote attackers to bypass access restrictions and perform unauthorized actions on other domains via a redirect.

    Published: 16 Jun 2005
    5
    Medium

    CVE-2005-2003

    Last Modified: 16 Apr 2026

    Ultimate PHP Board (UPB) 1.9.6 GOLD allows remote attackers to obtain sensitive information via an invalid (zero) id parameter to (1) viewtopic.php, (2) profile.php, or (3) newpost.php, which reveals the path in an error message.

    Published: 16 Jun 2005
    7.5
    High

    CVE-2005-2026

    Last Modified: 16 Apr 2026

    Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 has a hard-coded account and password for debugging, which allows remote attackers to gain privileges.

    Published: 16 Jun 2005
    5
    Medium

    CVE-2005-2027

    Last Modified: 16 Apr 2026

    Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 does not properly restrict certain debugging commands to the ADMIN account, which could allow attackers to obtain sensitive information or modify the registry.

    Published: 16 Jun 2005
    2.1
    Low

    CVE-2005-2032

    Last Modified: 16 Apr 2026

    Unknown vulnerability in lpadmin on Sun Solaris 7, 8, and 9 allows local users to overwrite arbitrary files.

    Published: 16 Jun 2005
    7.5
    High

    CVE-2005-2035

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in login.asp for Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to execute arbitrary SQL commands via the password.

    Published: 16 Jun 2005
    7.5
    High

    CVE-2005-2036

    Last Modified: 16 Apr 2026

    modifyUser.asp in Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to obtain the administrator password and email address via a modified nickname value.

    Published: 16 Jun 2005
    4.3
    Medium

    CVE-2005-2042

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in ajax-spell before 1.8 allows remote attackers to inject arbitrary web script or HTML via onmouseover or other events in HTML tags.

    Published: 16 Jun 2005
    6.8
    Medium

    CVE-2005-1669

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Opera 8.0 Final Build 1095 allows remote attackers to inject arbitrary web script or HTML via "javascript:" URLs when a new window or frame is opened, which allows remote attackers to bypass access restrictions and perform unauthorized actions on other domains.

    Published: 16 Jun 2005
    4.3
    Medium

    CVE-2005-2044

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.3 and 1.5 RC 1 allow remote attackers to inject arbitrary web script or HTML via the (1) show_course parameter to browse.php, (2) subject parameter to contact.php, (3) cid parameter to content.php, (4) l parameter to inbox/send_message.php, the (5) search, (6) words, (7) include, (8) find_in, (9) display_as, or (10) search parameter to search.php, the (11) submit, (12) query, or (13) field parameter to tile.php, the (14) us parameter to forum/subscribe_forum.php, or the (15) roles[], (16) status, (17) submit, or (18) reset_filter parameters to directory.php.

    Published: 16 Jun 2005
    7.5
    High

    CVE-2005-2031

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in socialMPN allow remote attackers to execute arbitrary SQL commands via (1) the sid parameter to article.php, (2) uname parameter to user.php, (3) siteid parameter to viewforum.php, (4) username parameter to newtopic.php, the (5) secid or (6) artid parameter to sections.php, (7) siteid parameter to index.php, or (8) sid parameter to friend.php.

    Published: 16 Jun 2005
    5
    Medium

    CVE-2005-2005

    Last Modified: 16 Apr 2026

    Ultimate PHP Board (UPB) 1.9.6 GOLD and earlier stores the users.dat file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information on registered users via a direct request to db/users.dat.

    Published: 16 Jun 2005
    5
    Medium

    CVE-2005-2030

    Last Modified: 16 Apr 2026

    Ultimate PHP Board (UPB) 1.9.6 GOLD uses weak encryption for passwords in the users.dat file, which allows attackers to easily decrypt the passwords and gain privileges, possibly after exploiting CVE-2005-2005 to obtain users.dat.

    Published: 16 Jun 2005
    5
    Medium

    CVE-2005-1995

    Last Modified: 16 Apr 2026

    Bitrix Site Manager 4.0.x allows remote attackers to obtain sensitive information via direct request to (1) subscr_form.php or (2) dbquery_error.php, which reveals the path in an error message.

    Published: 15 Jun 2005
    5
    Medium

    CVE-2005-1996

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via the _SERVER[DOCUMENT_ROOT] parameter.

    Published: 15 Jun 2005
    5
    Medium

    CVE-2005-2001

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in pafiledb.php in paFileDB 3.1 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) in the action parameter.

    Published: 15 Jun 2005
    7.5
    High

    CVE-2005-2002

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in content.php in Mambo 4.5.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_rating parameter.

    Published: 15 Jun 2005
    7.5
    High

    CVE-2005-2000

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the formname parameter (1) in the login form, (2) in the team login form, or (3) to auth.php, (4) select, (5) id, or (6) query parameter to pafiledb.php, or (7) string parameter to search.php.

    Published: 15 Jun 2005
    5
    Medium

    CVE-2005-1998

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in admin.php in McGallery 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.

    Published: 15 Jun 2005
    4.3
    Medium

    CVE-2005-1999

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in pafiledb.php in paFileDB 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) sortby or (2) filelist parameters to the category action (category.php), or (3) pages parameter in the viewall action (viewall.php).

    Published: 15 Jun 2005
    5
    Medium

    CVE-2005-2041

    Last Modified: 16 Apr 2026

    Buffer overflow in addschup in HAURI ViRobot 2.0, and possibly other products, allows remote attackers to execute arbitrary code via a long ViRobot_ID cookie (HTTP_COOKIE).

    Published: 15 Jun 2005
    7.5
    High

    CVE-2005-1306

    Last Modified: 16 Apr 2026

    The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulnerability."

    Published: 15 Jun 2005
    5
    Medium

    CVE-2005-1997

    Last Modified: 16 Apr 2026

    show.php in McGallery 1.1 allows remote attackers to connect to arbitrary databases, or gain sensitive information by triggering an error, via a modified host parameter.

    Published: 15 Jun 2005
    5
    Medium

    CVE-2005-1266

    Last Modified: 16 Apr 2026

    Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header without any boundaries.

    Published: 15 Jun 2005
    4.3
    Medium

    CVE-2005-1769

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.4 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in (1) the URL or (2) an e-mail message.

    Published: 15 Jun 2005
    5.1
    Medium

    CVE-2005-1211

    Last Modified: 16 Apr 2026

    Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file.

    Published: 14 Jun 2005
    7.5
    High

    CVE-2005-1213

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field.

    Published: 14 Jun 2005
    5.1
    Medium

    CVE-2005-1214

    Last Modified: 16 Apr 2026

    Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page.

    Published: 14 Jun 2005