CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2005-1408

    Last Modified: 16 Apr 2026

    Apple Keynote 2.0 and 2.0.1 allows remote attackers to read arbitrary files via the keynote: URI handler in a crafted Keynote presentation.

    Published: 26 May 2005
    5
    Medium

    CVE-2005-1522

    Last Modified: 16 Apr 2026

    The imap4d server for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows authenticated remote users to cause a denial of service (CPU consumption) via a large range value in the FETCH command.

    Published: 26 May 2005
    4.3
    Medium

    CVE-2005-1782

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in BookReview beta 1.0 allow remote attackers to inject arbitrary web script or HTML via the node parameter to (1) add_review.htm, (2) suggest_review.htm, (3) suggest_category.htm, (4) add_booklist.htm, or (5) add_url.htm, the isbn parameter to (6) add_review.htm, (7) add_contents.htm, (8) add_classification.htm, the (9) chapters parameter to the add_contents page in index.php (aka add_contents.htm), (10) the user parameter to contact.htm, or (11) the submit[string] parameter to search.htm. NOTE: it is not clear whether BookReview is available to the public. If not, then it should not be included in CVE.

    Published: 26 May 2005
    7.2
    High

    CVE-2005-1151

    Last Modified: 16 Apr 2026

    qpopper 4.0.5 and earlier does not properly drop privileges before processing certain user-supplied files, which allows local users to overwrite or create arbitrary files as root.

    Published: 25 May 2005
    5
    Medium

    CVE-2005-1252

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the Web Calendaring server in Ipswitch Imail 8.13, and other versions before IMail Server 8.2 Hotfix 2, allows remote attackers to read arbitrary files via "..\" (dot dot backslash) sequences in the query string argument in a GET request to a non-existent .jsp file.

    Published: 25 May 2005
    5
    Medium

    CVE-2005-1254

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the IMAP server for Ipswitch IMail 8.12 and 8.13, and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to cause a denial of service (crash) via a SELECT command with a large argument.

    Published: 25 May 2005
    10
    Critical

    CVE-2005-1256

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the IMAP daemon (IMAPD32.EXE) in IMail 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to execute arbitrary code via a STATUS command with a long mailbox name.

    Published: 25 May 2005
    7.5
    High

    CVE-2005-1750

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in login.asp in ezdwc NewsletterEz 3.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.

    Published: 25 May 2005
    7.5
    High

    CVE-2005-1786

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in admin.asp in FunkyASP AD System 1.1 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password parameter.

    Published: 25 May 2005
    10
    Critical

    CVE-2005-1255

    Last Modified: 16 Apr 2026

    Multiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allow remote attackers to execute arbitrary code via a LOGIN command with (1) a long username argument or (2) a long username argument that begins with a special character.

    Published: 25 May 2005
    2.1
    Low

    CVE-2005-1152

    Last Modified: 16 Apr 2026

    popauth.c in qpopper 4.0.5 and earlier does not properly set the umask, which may cause qpopper to create files with group or world-writable permissions.

    Published: 25 May 2005
    5
    Medium

    CVE-2005-1249

    Last Modified: 16 Apr 2026

    The IMAP daemon (IMAPD32.EXE) in Ipswitch Collaboration Suite (ICS) allows remote attackers to cause a denial of service (CPU consumption) via an LSUB command with a large number of null characters, which causes an infinite loop.

    Published: 25 May 2005
    7.5
    High

    CVE-2005-1543

    Last Modified: 16 Apr 2026

    Multiple stack-based and heap-based buffer overflows in Remote Management authentication (zenrem32.exe) on Novell ZENworks 6.5 Desktop and Server Management, ZENworks for Desktops 4.x, ZENworks for Servers 3.x, and Remote Management allows remote attackers to execute arbitrary code via (1) unspecified vectors, (2) type 1 authentication requests, and (3) type 2 authentication requests.

    Published: 25 May 2005
    7.5
    High

    CVE-2005-1692

    Last Modified: 16 Apr 2026

    Format string vulnerability in gxine 0.4.1 through 0.4.4, and other versions down to 0.3, allows remote attackers to execute arbitrary code via a ram file with a URL whose hostname contains format string specifiers.

    Published: 24 May 2005
    7.5
    High

    CVE-2005-1694

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Xanthia.php in the Xanthia module in PostNuke 0.750 allow remote attackers to execute arbitrary SQL commands via the (1) name or (2) module parameter.

    Published: 24 May 2005
    7.5
    High

    CVE-2005-1701

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in PortailPHP 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter to the (1) News, (2) File, (3) Liens, or (4) Faq modules.

    Published: 24 May 2005
    7.5
    High

    CVE-2005-1702

    Last Modified: 16 Apr 2026

    Format string vulnerability in Warrior Kings: Battles 1.23 and earlier and Warrior Kings 1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a nickname.

    Published: 24 May 2005
    4.6
    Medium

    CVE-2005-1707

    Last Modified: 16 Apr 2026

    The fn_show_postinst function in Gentoo webapp-config before 1.10-r14 allows local users to overwrite arbitrary files via a symlink attack on the postinst.txt temporary file.

    Published: 24 May 2005
    4.6
    Medium

    CVE-2005-1708

    Last Modified: 16 Apr 2026

    templates.admin.users.user_form_processing in Blue Coat Reporter before 7.1.2 allows authenticated users to gain administrator privileges via an HTTP POST that sets volatile.user.administrator to true.

    Published: 24 May 2005
    7.5
    High

    CVE-2005-1709

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Blue Coat Reporter before 7.1.2 allows remote unauthenticated attackers to add a license.

    Published: 24 May 2005
    4.3
    Medium

    CVE-2005-1710

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Blue Coat Reporter before 7.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the username in an Add User window or (2) the license key (volatile.license_to_add parameter) in the Licensing page.

    Published: 24 May 2005
    7.5
    High

    CVE-2005-1706

    Last Modified: 16 Apr 2026

    Unknown vulnerability in MailScanner 4.41.3 and earlier, related to "incomplete reporting of viruses in zip files," allows remote attackers to bypass virus detection.

    Published: 24 May 2005
    4.3
    Medium

    CVE-2005-1714

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 3.0c2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 24 May 2005
    5
    Medium

    CVE-2005-1716

    Last Modified: 16 Apr 2026

    TOPo 2.2 (2.2.178) stores data files in the data directory under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as client IP addresses.

    Published: 24 May 2005
    5
    Medium

    CVE-2005-1717

    Last Modified: 16 Apr 2026

    ZyXEL Prestige 650R-31 router running ZyNOS FW v3.40(KO.1) allows remote attackers to cause a denial of service (CPU consumption and network loss) via crafted fragmented IP packets.

    Published: 24 May 2005
    5
    Medium

    CVE-2005-1718

    Last Modified: 16 Apr 2026

    Buffer overflow in LS Games War Times 1.03 and earlier allows remote attackers to cause a denial of service (server crash) via a long nickname.

    Published: 24 May 2005
    7.5
    High

    CVE-2005-1719

    Last Modified: 16 Apr 2026

    Unknown vulnerability in ALWIL avast! antivirus 4 (4.6.6230) and earlier, when running on Windows NT 4.0, does not properly detect certain viruses.

    Published: 24 May 2005
    7.5
    High

    CVE-2005-1734

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in PROMS before 0.11 allow remote attackers to execute arbitrary SQL commands via unknown vectors.

    Published: 24 May 2005
    4.3
    Medium

    CVE-2005-1735

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PROMS before 0.11 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 24 May 2005
    7.5
    High

    CVE-2005-1736

    Last Modified: 16 Apr 2026

    PROMS 0.11 does not properly handle "certain combinations of rights," which gives more rights to users than intended.

    Published: 24 May 2005
    7.5
    High

    CVE-2005-1737

    Last Modified: 16 Apr 2026

    Multiple unknown vulnerabilities in PROMS 0.11 allow "non-authorized users" to (1) view or modify the project member list or (2) modify the todos list.

    Published: 24 May 2005
    5
    Medium

    CVE-2005-1741

    Last Modified: 16 Apr 2026

    Gearbox Software Halo: Combat Evolved 1.6 allows remote attackers to cause a denial of service (infinite loop) via malformed data.

    Published: 24 May 2005
    5
    Medium

    CVE-2005-1742

    Last Modified: 16 Apr 2026

    BEA WebLogic Server and WebLogic Express 8.1 SP2 and SP3 allows users with the Monitor security role to "shrink or reset JDBC connection pools."

    Published: 24 May 2005
    9.8
    Critical

    CVE-2005-1744

    Last Modified: 16 Apr 2026

    BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those users to continue to access the application without having to log in again, which may be in violation of newly changed security constraints or role mappings.

    Published: 24 May 2005
    10
    Critical

    CVE-2005-1693

    Last Modified: 16 Apr 2026

    Integer overflow in Computer Associates Vet Antivirus library, as used by CA InoculateIT 6.0, eTrust Antivirus r6.0 through 7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, BrightStor ARCserve Backup (BAB) r11.1, Vet Antivirus, Zonelabs ZoneAlarm Security Suite, and ZoneAlarm Antivirus, allows remote attackers to gain privileges via a compressed VBA directory with a project name length of -1, which leads to a heap-based buffer overflow.

    Published: 24 May 2005
    2.6
    Low

    CVE-2005-1695

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allow remote attackers to inject arbitrary web script or HTML via the (1) rss_url parameter to magpie_slashbox.php, or the url parameter to (2) magpie_simple.php or (3) magpie_debug.php.

    Published: 24 May 2005
    4
    Medium

    CVE-2005-1699

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in pnadminapi.php in the Xanthia module in PostNuke 0.760-RC3 allows remote administrators to read arbitrary files via a .. (dot dot) in the skin parameter.

    Published: 24 May 2005
    7.5
    High

    CVE-2005-1700

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in pnadmin.php in the Xanthia module in PostNuke 0.760-RC3 allows remote administrators to execute arbitrary SQL commands via the riga[0] parameter.

    Published: 24 May 2005
    7.2
    High

    CVE-2005-1705

    Last Modified: 16 Apr 2026

    gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which allows local users to execute arbitrary commands as the user running gdb.

    Published: 24 May 2005
    4.3
    Medium

    CVE-2005-1713

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Serendipity 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) templatedropdown and (2) shoutbox plugins.

    Published: 24 May 2005
    4.3
    Medium

    CVE-2005-1715

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php for TOPo 2.2 (2.2.178) allows remote attackers to inject arbitrary web script or HTML via the (1) m, (2) s, (3) ID, or (4) t parameters, or the (5) field name, (6) Your Web field, or (7) email field in the comments section.

    Published: 24 May 2005
    5
    Medium

    CVE-2005-1732

    Last Modified: 16 Apr 2026

    Cookie Cart allows remote attackers to read the Order Notification list via the testmycgi and path parameters to testmy.cgi.

    Published: 24 May 2005
    5
    Medium

    CVE-2005-1733

    Last Modified: 16 Apr 2026

    Cookie Cart stores the password file under the web document root with insufficient access control, which allows remote attackers to obtain usernames and encrypted passwords via a direct request to passwd.txt.

    Published: 24 May 2005
    7.5
    High

    CVE-2005-1743

    Last Modified: 16 Apr 2026

    BEA WebLogic Server and WebLogic Express 8.1 through Service Pack 3 and 7.0 through Service Pack 5 does not properly handle when a security provider throws an exception, which may cause WebLogic to use incorrect identity for the thread, or to fail to audit security exceptions.

    Published: 24 May 2005
    4.6
    Medium

    CVE-2005-1745

    Last Modified: 16 Apr 2026

    The UserLogin control in BEA WebLogic Portal 8.1 through Service Pack 3 prints the password to standard output when an incorrect login attempt is made, which could make it easier for attackers to guess the correct password.

    Published: 24 May 2005
    5
    Medium

    CVE-2005-1697

    Last Modified: 16 Apr 2026

    The RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allows remote attackers to obtain sensitive information via a direct request to simple_smarty.php, which reveals the path in an error message.

    Published: 24 May 2005
    5
    Medium

    CVE-2005-1698

    Last Modified: 16 Apr 2026

    PostNuke 0.750 and 0.760RC3 allows remote attackers to obtain sensitive information via a direct request to (1) theme.php or (2) Xanthia.php in the Xanthia module, (3) user.php, (4) thelang.php, (5) text.php, (6) html.php, (7) menu.php, (8) finclude.php, or (9) button.php in the pnblocks directory in the Blocks module, (10) config.php in the NS-Multisites (aka Multisites) module, or (11) xmlrpc.php, which reveals the path in an error message.

    Published: 24 May 2005
    7.5
    High

    CVE-2005-1711

    Last Modified: 16 Apr 2026

    Gibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses, which does not return an error code and prevents viruses from being detected.

    Published: 24 May 2005
    7.5
    High

    CVE-2005-1712

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Serendipity 0.8, when used with multiple authors, allows unprivileged authors to upload arbitrary media files.

    Published: 24 May 2005
    5
    Medium

    CVE-2005-1748

    Last Modified: 16 Apr 2026

    The embedded LDAP server in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 5, allows remote anonymous binds, which may allow remote attackers to view user entries or cause a denial of service.

    Published: 24 May 2005