CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2005-1747

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 6, allow remote attackers to inject arbitrary web script or HTML, and possibly gain administrative privileges, via the (1) j_username or (2) j_password parameters in the login page (LoginForm.jsp), (3) parameters to the error page in the Administration Console, (4) unknown vectors in the Server Console while the administrator has an active session to obtain the ADMINCONSOLESESSION cookie, or (5) an alternate vector in the Server Console that does not require an active session but also leaks the username and password.

    Published: 24 May 2005
    5
    Medium

    CVE-2005-1749

    Last Modified: 16 Apr 2026

    Buffer overflow in BEA WebLogic Server and WebLogic Express 6.1 Service Pack 4 allows remote attackers to cause a denial of service (CPU consumption from thread looping).

    Published: 24 May 2005
    2.6
    Low

    CVE-2005-1696

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.750 and 0.760RC3 allow remote attackers to inject arbitrary web script or HTML via the (1) skin or (2) paletteid parameter to demo.php in the Xanthia module, or (3) the serverName parameter to config.php in the Multisites (aka NS-Multisites) module.

    Published: 24 May 2005
    5
    Medium

    CVE-2005-1703

    Last Modified: 16 Apr 2026

    Warrior Kings: Battles 1.23 and earlier allows remote attackers to cause a denial of service (server crash) via a partial join packet that triggers a NULL pointer dereference.

    Published: 24 May 2005
    4.6
    Medium

    CVE-2005-1704

    Last Modified: 16 Apr 2026

    Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, and possibly other packages, allows user-assisted attackers to execute arbitrary code via a crafted object file that specifies a large number of section headers, leading to a heap-based buffer overflow.

    Published: 24 May 2005
    10
    Critical

    CVE-2005-1738

    Last Modified: 16 Apr 2026

    Format string vulnerability in the logPrintBadfile function in delbadfiles.c Iron Bars SHell (ibsh) before 0.3d allows users to "access files outside the home directory" and possibly execute arbitrary code via certain inputs that are not properly handled in a syslog call.

    Published: 24 May 2005
    5
    Medium

    CVE-2005-1746

    Last Modified: 16 Apr 2026

    The cluster cookie parsing code in BEA WebLogic Server 7.0 through Service Pack 5 attempts to contact any host or port specified in a cookie, even when it is not in the cluster, which allows remote attackers to cause a denial of service (cluster slowdown) via modified cookies.

    Published: 24 May 2005
    3.7
    Low

    CVE-2005-1751

    Last Modified: 16 Apr 2026

    Race condition in shtool 2.0.1 and earlier allows local users to create or modify arbitrary files via a symlink attack on the .shtool.$$ temporary file, a different vulnerability than CVE-2005-1759.

    Published: 24 May 2005
    7.5
    High

    CVE-2006-2314

    Last Modified: 16 Apr 2026

    PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications that use multibyte encodings that allow the "\" (backslash) byte 0x5c to be the trailing byte of a multibyte character, such as SJIS, BIG5, GBK, GB18030, and UHC, which cannot be handled correctly by a client that does not understand multibyte encodings, aka a second variant of "Encoding-Based SQL Injection." NOTE: it could be argued that this is a class of issue related to interaction errors between the client and PostgreSQL, but a CVE has been assigned since PostgreSQL is treating this as a preventative measure against this class of problem.

    Published: 23 May 2005
    10
    Critical

    CVE-2005-4837

    Last Modified: 16 Apr 2026

    snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allows remote attackers to cause a denial of service (crash) by causing a particular TCP disconnect, which triggers a free of an incorrect variable, a different vulnerability than CVE-2005-2177.

    Published: 23 May 2005
    7.5
    High

    CVE-2006-2313

    Last Modified: 16 Apr 2026

    PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications via invalid encodings of multibyte characters, aka one variant of "Encoding-Based SQL Injection."

    Published: 23 May 2005
    7.5
    High

    CVE-2005-1677

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 allows remote attackers to bypass restrictions on COM objects.

    Published: 20 May 2005
    2.6
    Low

    CVE-2005-1678

    Last Modified: 16 Apr 2026

    Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 does not properly display file extensions on attached or embedded files in a compound document, which may allow remote attackers to trick users into executing malicious code.

    Published: 20 May 2005
    5.1
    Medium

    CVE-2005-1679

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the error directive in picasm 1.12b and earlier allows attackers to execute arbitrary code via a long error message.

    Published: 20 May 2005
    7.5
    High

    CVE-2005-1680

    Last Modified: 16 Apr 2026

    D-Link DSL-502T, DSL-504T, DSL-562T, and DSL-G604T, when /cgi-bin/firmwarecfg is executed, allows remote attackers to bypass authentication (1) if their IP address already exists in /var/tmp/fw_ip or (2) if their request is the first, which causes /var/tmp/fw_ip to be created and contain their IP address.

    Published: 20 May 2005
    4.3
    Medium

    CVE-2005-1684

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in default.asp for episodex guestbook allows remote attackers to inject arbitrary web script or HTML via the Name field and other fields.

    Published: 20 May 2005
    7.5
    High

    CVE-2005-1685

    Last Modified: 16 Apr 2026

    episodex guestbook allows remote attackers to bypass authentication and edit scripts via a direct request to admin.asp.

    Published: 20 May 2005
    7.5
    High

    CVE-2005-1687

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in wp-trackback.php in Wordpress 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the tb_id parameter.

    Published: 20 May 2005
    4.6
    Medium

    CVE-2005-1675

    Last Modified: 16 Apr 2026

    Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 installs the client installation directories with insecure EVERYBODY permissions, which allows local users to gain sensitive information.

    Published: 20 May 2005
    6.8
    Medium

    CVE-2005-1676

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Groove Mobile Workspace in Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 allow remote attackers to inject arbitrary web script or HTML via the (1) picture columns embedded within SharePoint lists or (2) drop-down menus in a SharePoint list.

    Published: 20 May 2005
    2.1
    Low

    CVE-2005-1682

    Last Modified: 16 Apr 2026

    JavaMail API, as used by Solstice Internet Mail Server POP3 2.0, does not properly validate the message number in the MimeMessage constructor in javax.mail.internet.InternetHeaders, which allows remote authenticated users to read other users' e-mail messages by modifying the msgno parameter. NOTE: Sun disputes this issue, stating "The report makes references to source code and files that do not exist in the mentioned products.

    Published: 20 May 2005
    2.6
    Low

    CVE-2005-1683

    Last Modified: 16 Apr 2026

    Buffer overflow in winword.exe 10.2627.6714 and earlier in Microsoft Word for the Macintosh, before SP3 for Word 2002, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted mcw file.

    Published: 20 May 2005
    5.3
    Medium

    CVE-2005-1688

    Last Modified: 16 Apr 2026

    Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message.

    Published: 20 May 2005
    7.5
    High

    CVE-2005-1681

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in common.php in phpATM 1.21, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the include_location parameter to index.php.

    Published: 20 May 2005
    2.6
    Low

    CVE-2005-1686

    Last Modified: 16 Apr 2026

    Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string specifiers in the filename. NOTE: while this issue is triggered on the command line by the gedit user, it has been reported that web browsers and email clients could be configured to provide a file name as an argument to gedit, so there is a valid attack that crosses security boundaries.

    Published: 20 May 2005
    7.2
    High

    CVE-2005-1763

    Last Modified: 16 Apr 2026

    Buffer overflow in ptrace in the Linux Kernel for 64-bit architectures allows local users to write bytes into kernel memory.

    Published: 20 May 2005
    7.5
    High

    CVE-2005-1673

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Help Center Live allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to index.php, (2) tid parameter to view.php, fid parameter to (3) download.php or (4) chat_download.php, (5) status parameter to icon.php, TICKET_tid parameter to (6) index.php or (7) view.php.

    Published: 19 May 2005
    2.1
    Low

    CVE-2005-1472

    Last Modified: 16 Apr 2026

    Certain system calls in Apple Mac OS X 10.4.1 do not properly enforce the permissions of certain directories without the POSIX read bit set, but with the execute bits set for group or other, which allows local users to list files in otherwise restricted directories.

    Published: 19 May 2005
    4.6
    Medium

    CVE-2005-1670

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Extreme BlackDiamond 10808 and 8800 switches running ExtremeWare XOS 11.1 before 11.1.3.3, 11.0 before 11.0.2.4, and 10.x allows remote authenticated users to execute arbitrary commands.

    Published: 19 May 2005
    2.1
    Low

    CVE-2005-1671

    Last Modified: 16 Apr 2026

    The Logfile feature in Yahoo! Messenger 5.x through 6.0 can be activated by a YMSGR: URL and writes all output to a single ypager.log file, even when there are multiple users, and does not properly warn later users that the feature has been enabled, which allows local users to obtain sensitive information from other users.

    Published: 19 May 2005
    4.3
    Medium

    CVE-2005-1672

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Help Center Live allow remote attackers to inject arbitrary web script or HTML via the (1) find parameter to index.php, (2) name or (3) message field of a chat request, or (4) the message body when opening a trouble ticket.

    Published: 19 May 2005
    5
    Medium

    CVE-2005-1934

    Last Modified: 16 Apr 2026

    Gaim before 1.3.1 allows remote attackers to cause a denial of service (crash) via a malformed MSN message that leads to a memory allocation of a large size, possibly due to an integer signedness error.

    Published: 19 May 2005
    4.3
    Medium

    CVE-2005-0040

    Last Modified: 24 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in DotNetNuke before 3.0.12 allow remote attackers to inject arbitrary web script or HTML via the (1) register a new user page, (2) User-Agent, or (3) Username, which is not properly quoted before sending to the error log.

    Published: 19 May 2005
    6.5
    Medium

    CVE-2005-1674

    Last Modified: 16 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Help Center Live allows remote attackers to perform actions as the administrator via a link or IMG tag to view.php.

    Published: 19 May 2005
    7.2
    High

    CVE-2005-0392

    Last Modified: 16 Apr 2026

    ppxp does not drop root privileges before opening log files, which allows local users to execute arbitrary commands.

    Published: 19 May 2005
    2.1
    Low

    CVE-2005-1265

    Last Modified: 16 Apr 2026

    The mmap function in the Linux Kernel 2.6.10 can be used to create memory maps with a start address beyond the end address, which allows local users to cause a denial of service (kernel crash).

    Published: 19 May 2005
    5
    Medium

    CVE-2005-1645

    Last Modified: 16 Apr 2026

    Keyvan1 ImageGallery stores the image.mdb database under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.

    Published: 18 May 2005
    7.5
    High

    CVE-2005-1651

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in the wmm parameter.

    Published: 18 May 2005
    7.5
    High

    CVE-2005-1652

    Last Modified: 16 Apr 2026

    message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to bypass authentication by modifying the email parameter.

    Published: 18 May 2005
    6.8
    Medium

    CVE-2005-1653

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to inject arbitrary web script or HTML via the email parameter.

    Published: 18 May 2005
    7.5
    High

    CVE-2005-1654

    Last Modified: 16 Apr 2026

    Hosting Controller 6.1 Hotfix 1.9 and earlier allows remote attackers to register arbitrary users via a direct request to addsubsite.asp with the loginname and password parameters set.

    Published: 18 May 2005
    5
    Medium

    CVE-2005-1655

    Last Modified: 16 Apr 2026

    AOL Instant Messenger 5.5.x and earlier allows remote attackers to cause a denial of service (client crash) via an invalid smiley icon location in the sml parameter of a font tag.

    Published: 18 May 2005
    7.5
    High

    CVE-2005-1660

    Last Modified: 16 Apr 2026

    HTMLJunction EZGuestbook stores the guestbook.mdb file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the administrative password.

    Published: 18 May 2005
    5
    Medium

    CVE-2005-1661

    Last Modified: 16 Apr 2026

    Jeuce Personal Webserver 2.13 allows remote attackers to cause a denial of service (server crash) via a long GET request, possibly triggering a buffer overflow.

    Published: 18 May 2005
    5
    Medium

    CVE-2005-1662

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Jeuce Personal Web Server 2.13 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

    Published: 18 May 2005
    5
    Medium

    CVE-2005-1663

    Last Modified: 16 Apr 2026

    Jeuce Personal Web Server 2.13 allows remote attackers to cause a denial of service (server crash) via a GET request beginning with "://".

    Published: 18 May 2005
    7.5
    High

    CVE-2005-1668

    Last Modified: 16 Apr 2026

    YusASP Web Asset Manager 1.0 allows remote attackers to gain privileges via a direct request to assetmanager.asp.

    Published: 18 May 2005
    5
    Medium

    CVE-2005-1667

    Last Modified: 16 Apr 2026

    DataTrac Activity Console 1.1 allows remote attackers to cause a denial of service via a long HTTP GET request.

    Published: 18 May 2005
    6.8
    Medium

    CVE-2005-1644

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in guestbook.php for 1Two Livre d'Or 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) livreornom, (2) livreoremail, or (3) livreormessage parameters.

    Published: 18 May 2005
    7.5
    High

    CVE-2005-1646

    Last Modified: 16 Apr 2026

    The default installation of Fastream NETFile FTP/Web Server 7.4.6, which supports FXP, does not require that the IP address in a PORT command be the same as the IP of the logged in user, which allows remote attackers to conduct FTP Bounce attacks to bypass firewall rules or cause a denial of service.

    Published: 18 May 2005