CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2005-1566

    Last Modified: 16 Apr 2026

    Acrowave AAP-3100AR wireless router allows remote attackers to bypass authentication by pressing CTRL-C at the username or password prompt in a telnet session, which causes the shell to crash and restart, then leave the user in the new shell.

    Published: 14 May 2005
    5
    Medium

    CVE-2005-1575

    Last Modified: 16 Apr 2026

    The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows allows remote attackers to hide the real file types of downloaded files via the Content-Type HTTP header and a filename containing whitespace, dots, or ASCII byte 160.

    Published: 14 May 2005
    4.3
    Medium

    CVE-2005-1584

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php for Quick.Forum 2.1.6 allows remote attackers to inject arbitrary web script or HTML via the topic field in a NewTopic action.

    Published: 14 May 2005
    2.1
    Low

    CVE-2005-1578

    Last Modified: 16 Apr 2026

    EnCase Forensic Edition 4.18a does not support Device Configuration Overlays (DCO), which allows attackers to hide information without detection.

    Published: 13 May 2005
    4.6
    Medium

    CVE-2005-0969

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the syscall emulation functionality in Mac OS X before 10.3.9 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via crafted parameters.

    Published: 12 May 2005
    4.6
    Medium

    CVE-2005-0971

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the semop system call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.

    Published: 12 May 2005
    7.2
    High

    CVE-2005-0972

    Last Modified: 16 Apr 2026

    Integer overflow in the searchfs system call in Mac OS X 10.3.9 and earlier allows local users to execute arbitrary code via crafted parameters.

    Published: 12 May 2005
    2.1
    Low

    CVE-2005-0973

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the setsockopt system call in Mac OS X 10.3.9 and earlier allows local users to cause a denial of service (memory exhaustion) via crafted arguments.

    Published: 12 May 2005
    Unknown

    CVE-2005-1271

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-1343. Reason: This candidate is a reservation duplicate of CVE-2005-1343. Notes: All CVE users should reference CVE-2005-1343 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 12 May 2005
    5
    Medium

    CVE-2005-1565

    Last Modified: 16 Apr 2026

    Bugzilla 2.17.1 through 2.18, 2.19.1, and 2.19.2, when a user is prompted to log in while attempting to view a chart, displays the password in the URL, which may allow local users to gain sensitive information from web logs or browser history.

    Published: 12 May 2005
    5
    Medium

    CVE-2005-1568

    Last Modified: 16 Apr 2026

    topic.php in DirectTopics 2.1 and 2.2 allows remote attackers to obtain sensitive information via an invalid topic parameter, which reveals the path in an error message.

    Published: 12 May 2005
    7.5
    High

    CVE-2005-1567

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in topic.php in DirectTopics 2.1 and 2.2 allows remote attackers to execute arbitrary SQL commands via the topic parameter.

    Published: 12 May 2005
    5
    Medium

    CVE-2005-1579

    Last Modified: 16 Apr 2026

    Apple QuickTime Player 7.0 on Mac OS X 10.4 allows remote attackers to obtain sensitive information via a .mov file with a Quartz Composer composition (.qtz) file that uses certain patches to read local information, then other patches to send the information to the attacker.

    Published: 12 May 2005
    2.6
    Low

    CVE-2005-1576

    Last Modified: 16 Apr 2026

    The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows uses the Content-Type HTTP header to determine the file type, but saves the original file extension when "Save to Disk" is selected, which allows remote attackers to hide the real file types of downloaded files.

    Published: 12 May 2005
    7.5
    High

    CVE-2005-1532

    Last Modified: 16 Apr 2026

    Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.

    Published: 12 May 2005
    7.2
    High

    CVE-2005-0974

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the nfs_mount call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.

    Published: 12 May 2005
    7.5
    High

    CVE-2005-1531

    Last Modified: 16 Apr 2026

    Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) "a nested variant."

    Published: 12 May 2005
    7.5
    High

    CVE-2005-1564

    Last Modified: 16 Apr 2026

    post_bug.cgi in Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 allows remote authenticated users to "enter bugs into products that are closed for bug entry" by modifying the URL to specify the name of the product.

    Published: 12 May 2005
    7.5
    High

    CVE-2005-1478

    Last Modified: 16 Apr 2026

    Format string vulnerability in dSMTP (dsmtp.exe) in DMail 3.1a allows remote attackers to execute arbitrary code via format string specifiers in the xtellmail command.

    Published: 11 May 2005
    7.5
    High

    CVE-2005-1479

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in jgs_portal.php in JGS-Portal 3.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 11 May 2005
    5
    Medium

    CVE-2005-1484

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Golden FTP server pro 2.52 allows remote attackers to read arbitrary files via a "\.." (backward slash dot dot) with a leading '"' (double quote) in the GET command.

    Published: 11 May 2005
    5
    Medium

    CVE-2005-1486

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting vulnerabilities in FishCart 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) trackingnum, (2) reqagree, or (3) m parameter to upstracking.php or (4) nlst parameter to display.php. NOTE: the vendor was not able to reproduce some of the reported vectors but believes that they have been addressed. The original researcher is known to be unreliable.

    Published: 11 May 2005
    7.5
    High

    CVE-2005-1487

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in FishCart 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) cartid parameter to upstnt.php or (2) psku parameter to display.php. NOTE: the vendor disputes this report, saying that they are forced SQL errors. The original researcher is known to be unreliable

    Published: 11 May 2005
    7.5
    High

    CVE-2005-1482

    Last Modified: 16 Apr 2026

    ArticleLive 2005 allows remote attackers to gain privileges by modifying the (1) auth and (2) userId fields in a cookie.

    Published: 11 May 2005
    4.6
    Medium

    CVE-2005-1491

    Last Modified: 16 Apr 2026

    Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to (1) move their home directory via viewaction.html or (2) move arbitrary files via the importfile parameter to importaction.html.

    Published: 11 May 2005
    4.3
    Medium

    CVE-2005-1492

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in user.cgi in Gossamer Threads Links SQL 2.x and 3.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter.

    Published: 11 May 2005
    5
    Medium

    CVE-2005-1493

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in SimpleCam 1.2 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the URL.

    Published: 11 May 2005
    4.3
    Medium

    CVE-2005-1494

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in admin.cgi in MegaBook 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) entryid or (2) password parameter.

    Published: 11 May 2005
    7.5
    High

    CVE-2005-1499

    Last Modified: 16 Apr 2026

    delcomment.php in myBloggie 2.1.1 allows remote attackers to delete arbitrary comments by modifying the comment_id parameter.

    Published: 11 May 2005
    7.5
    High

    CVE-2005-1500

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in myBloggie 2.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the keyword parameter in search.php; or (2) the date_no parameter in viewdate mode, (3) the cat_id parameter in viewcat mode, the (4) month_no or (5) year parameter in viewmonth mode, or (6) post_id parameter in viewid mode to index.php. NOTE: item (1) was discovered to affect 2.1.3 as well.

    Published: 11 May 2005
    7.5
    High

    CVE-2005-1501

    Last Modified: 16 Apr 2026

    MidiCart PHP Shopping Cart allows remote attackers to obtain sensitive information via a direct request to (1) search_list.php, (2) item_list.php, or (3) item_show.php, which reveal the path in a PHP error message.

    Published: 11 May 2005
    6.8
    Medium

    CVE-2005-1502

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in MidiCart PHP Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the (1) searchstring parameter to search_list.php or the (2) secondgroup or (3) maingroup parameters to item_list.php.

    Published: 11 May 2005
    7.5
    High

    CVE-2005-1503

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in MidiCart PHP Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) searchstring parameter to search_list.php, the (2) maingroup or (3) secondgroup parameters to item_list.php, or (4) code_no parameter to item_show.php.

    Published: 11 May 2005
    5
    Medium

    CVE-2005-1507

    Last Modified: 16 Apr 2026

    Buffer overflow in the Tomcat plugin in 4d WebSTAR 5.33 and 5.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long URL.

    Published: 11 May 2005
    6.8
    Medium

    CVE-2005-1508

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PwsPHP 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) month or (2) annee parameters to the news module, (3) nbractif or (4) annee parameters to the stats module, (5) id parameter to profil.php, (6) mb_lettre or (7) lettre parameter to memberlist.php, or (8) chaine_search, or (9) auteur_search parameter to the recherche module.

    Published: 11 May 2005
    7.5
    High

    CVE-2005-1509

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in profil.php in PwsPHP 1.2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 11 May 2005
    7.5
    High

    CVE-2005-1510

    Last Modified: 16 Apr 2026

    PwsPHP 1.2.2 allows remote attackers to obtain sensitive information via a direct request to the admin directory, which reveals the path in an error message.

    Published: 11 May 2005
    7.5
    High

    CVE-2005-1511

    Last Modified: 16 Apr 2026

    PwsPHP 1.2.2 allows remote attackers to bypass authentication and post arbitrary comments via the Pseudo cookie.

    Published: 11 May 2005
    7.5
    High

    CVE-2005-1512

    Last Modified: 16 Apr 2026

    The Admin panel in PwsPHP 1.2.2 does not properly verify uploaded picture files, which allows remote attackers to upload and possibly execute arbitrary files.

    Published: 11 May 2005
    7.5
    High

    CVE-2005-1506

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in out.php in CJ Ultra (CJUltra) Plus 1.0.3 and 1.0.4 allows remote attackers to execute arbitrary SQL commands via the perm parameter.

    Published: 11 May 2005
    7.5
    High

    CVE-2005-1516

    Last Modified: 16 Apr 2026

    DList (dlist.exe) in DMail 3.1a allows remote attackers to bypass authentication, read log files, and shutdown the system via a sendlog command with an incorrect password hash, which is not properly handled by the _cmd_sendlog function.

    Published: 11 May 2005
    7.5
    High

    CVE-2005-1517

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Cisco Firewall Services Module (FWSM) 2.3.1 and earlier, when using URL, FTP, or HTTPS filtering exceptions, allows certain TCP packets to bypass access control lists (ACLs).

    Published: 11 May 2005
    5
    Medium

    CVE-2005-1515

    Last Modified: 16 Apr 2026

    Integer signedness error in the qmail_put and substdio_put functions in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large number of SMTP RCPT TO commands.

    Published: 11 May 2005
    10
    Critical

    CVE-2005-1560

    Last Modified: 16 Apr 2026

    The SSH module in Neteyes Nexusway allows remote attackers to execute arbitrary commands via shell metacharacters in arguments to certain commands, as demonstrated using ping and traceroute.

    Published: 11 May 2005
    5
    Medium

    CVE-2005-1572

    Last Modified: 16 Apr 2026

    ShowOff! 1.5.4 allows remote attackers to cause a denial of service (server crash) via a malformed request to port 8083.

    Published: 11 May 2005
    7.5
    High

    CVE-2005-1573

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in admin_login.asp for ASP Virtual News Manager allows remote attackers to execute arbitrary SQL commands via the password parameter.

    Published: 11 May 2005
    7.5
    High

    CVE-2005-1580

    Last Modified: 16 Apr 2026

    users.ini.php in BoastMachine 3.0 does not properly restrict the types of files that can be uploaded, which allows remote attackers to execute arbitrary code.

    Published: 11 May 2005
    7.5
    High

    CVE-2005-1588

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to execute arbitrary SQL commands via the iCategory parameter. NOTE: the vendor has privately disputed this issue, saying that Quick.cart does not even use SQL and therefore can not be vulnerable to SQL injection

    Published: 11 May 2005
    4.3
    Medium

    CVE-2005-1483

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ArticleLive 2005 allow remote attackers to inject arbitrary web script or HTML via the (1) Query, (2) Username, (3) LastName, (4) Biography, or (5) BlogId parameter.

    Published: 11 May 2005
    1.9
    Low

    CVE-2005-1488

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) the E-mail address, Note, or Public Certificate fields to address.html, (2) addressaction.html, (3) the Signature field to settings.html, or (4) the Shared calendars to calendarsettings.html.

    Published: 11 May 2005