CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2005-1490

    Last Modified: 16 Apr 2026

    Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2, when the mailbox.dat file does not exist, allows remote authenticated users to determine if a file exists via the folder parameter to attachment.html.

    Published: 11 May 2005
    5
    Medium

    CVE-2005-1497

    Last Modified: 16 Apr 2026

    index.php in myBloggie 2.1.1 allows remote attackers to obtain sensitive information via an invalid post_id parameter, which reveals the path in an error message.

    Published: 11 May 2005
    4.3
    Medium

    CVE-2005-1498

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in myBloggie 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) year parameter in viewmode.php, or the (2) cat_id, (3) month_no, or (4) post_id parameter in index.php, which are not properly sanitized before they are displayed in an error message. NOTE: issues 2, 3, and 4 may be due to a problem in associated products rather than myBloggie itself.

    Published: 11 May 2005
    7.5
    High

    CVE-2005-1558

    Last Modified: 16 Apr 2026

    The web module in Neteyes Nexusway allows remote attackers to bypass authentication and gain administrator privileges by setting the cyclone500_auth cookie.

    Published: 11 May 2005
    4.3
    Medium

    CVE-2005-1561

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in post.asp in MaxWebPortal 1.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mod, (2) M, or (3) type parameter.

    Published: 11 May 2005
    7.5
    High

    CVE-2005-1562

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in MaxWebPortal 1.3.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fpassword parameter to inc_functions.asp, (2) txtAddress, (3) message, or (4) subject parameter to post_info.asp, (5) andor parameter to search.asp, (6) verkey parameter to pop_profile.asp, or (7) Remove or (8) Delete parameter to pm_delete2.asp.

    Published: 11 May 2005
    5
    Medium

    CVE-2005-1480

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in RaidenFTPD before 2.4.2241 allows remote attackers to read arbitrary files via a "..\\" (dot dot backslash) in the urlget site command.

    Published: 11 May 2005
    7.5
    High

    CVE-2005-1481

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Aaron Outpost ASP Inline Corporate Calendar allow remote attackers to execute arbitrary SQL commands via the Event_ID parameter to (1) defer.asp or (2) details.asp.

    Published: 11 May 2005
    5
    Medium

    CVE-2005-1485

    Last Modified: 16 Apr 2026

    Golden FTP Server Pro 2.52 allows remote attackers to obtain sensitive information via a GET request for a file that does not exist, which reveals the absolute path of the FTP server in the resulting FTP error message.

    Published: 11 May 2005
    5
    Medium

    CVE-2005-1489

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to obtain the full path of the server via certain requests to (1) calendar_addevent.html, (2) calendar_event.html, or (3) calendar_task.html.

    Published: 11 May 2005
    7.5
    High

    CVE-2005-1505

    Last Modified: 16 Apr 2026

    The new account wizard in Mail.app 2.0 in Mac OS 10.4, when configuring an IMAP mail account and checking the credentials, does not prompt the user to use SSL until after the password has already been sent, which causes the password to be sent in plaintext.

    Published: 11 May 2005
    5
    Medium

    CVE-2005-1514

    Last Modified: 16 Apr 2026

    commands.c in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long SMTP command without a space character, which causes an array to be referenced with a negative index.

    Published: 11 May 2005
    10
    Critical

    CVE-2005-1559

    Last Modified: 16 Apr 2026

    The web module in Neteyes Nexusway allows remote attackers to execute arbitrary commands via hex-encoded shell metacharacters in the ip parameter for (1) nslookup.cgi or (2) ping.cgi.

    Published: 11 May 2005
    7.5
    High

    CVE-2005-1585

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Quick.Forum 2.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) iCategory or (2) page parameter to index.php, or (3) iCategory parameter in the query string to the forum directory.

    Published: 11 May 2005
    7.5
    High

    CVE-2005-1495

    Last Modified: 16 Apr 2026

    Oracle Database 9i and 10g disables Fine Grained Audit (FGA) after the SYS user executes a SELECT statement on an FGA object, which makes it easier for attackers to escape detection.

    Published: 11 May 2005
    4.6
    Medium

    CVE-2005-1496

    Last Modified: 16 Apr 2026

    The DBMS_Scheduler in Oracle 10g allows remote attackers with CREATE JOB privileges to gain additional privileges by changing SESSION_USER to the SYS user.

    Published: 11 May 2005
    5
    Medium

    CVE-2005-1504

    Last Modified: 16 Apr 2026

    GameSpy SDK CD-Key Validation Toolkit, as used by many online games, allows remote attackers to bypass the CD key validation by sending a spoofed \disc\ command, which tells the server the CD key is no longer in use.

    Published: 11 May 2005
    2.1
    Low

    CVE-2005-1518

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Solaris 7 through 9, when using Federated Naming Services (FNS), autofs, and FNS X.500 configuration, allows local users to cause a denial of service (automountd crash) when "accessing" /xfn/_x500.

    Published: 11 May 2005
    4.3
    Medium

    CVE-2005-1557

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in WebApp Guestbook PRO 3.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message.

    Published: 11 May 2005
    6.4
    Medium

    CVE-2005-1519

    Last Modified: 16 Apr 2026

    Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attackers to spoof DNS lookups.

    Published: 11 May 2005
    5
    Medium

    CVE-2005-1262

    Last Modified: 16 Apr 2026

    Gaim 1.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed MSN message.

    Published: 11 May 2005
    7.2
    High

    CVE-2005-1263

    Last Modified: 16 Apr 2026

    The elf_core_dump function in binfmt_elf.c for Linux kernel 2.x.x to 2.2.27-rc2, 2.4.x to 2.4.31-pre1, and 2.6.x to 2.6.12-rc4 allows local users to execute arbitrary code via an ELF binary that, in certain conditions involving the create_elf_tables function, causes a negative length argument to pass a signed integer comparison, leading to a buffer overflow.

    Published: 11 May 2005
    7.5
    High

    CVE-2005-1261

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the URL parsing function in Gaim before 1.3.0 allows remote attackers to execute arbitrary code via an instant message (IM) with a large URL.

    Published: 11 May 2005
    9.8
    Critical

    CVE-2005-1513

    Last Modified: 16 Apr 2026

    Integer overflow in the stralloc_readyplus function in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large SMTP request.

    Published: 11 May 2005
    4.3
    Medium

    CVE-2005-1555

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the JRun Web Server in ColdFusion MX 7.0 allows remote attackers to inject arbitrary script or HTML via the URL, which is not properly quoted in the resulting default 404 error page.

    Published: 10 May 2005
    6.4
    Medium

    CVE-2005-0039

    Last Modified: 16 Apr 2026

    Certain configurations of IPsec, when using Encapsulating Security Payload (ESP) in tunnel mode, integrity protection at a higher layer, or Authentication Header (AH), allow remote attackers to decrypt IPSec communications by modifying the outer packet in ways that cause plaintext data from the inner packet to be returned in ICMP messages, as demonstrated using bit-flipping attacks and (1) Destination Address Rewriting, (2) a modified header length that causes portions of the packet to be interpreted as IP Options, or (3) a modified protocol field and source address.

    Published: 10 May 2005
    2.1
    Low

    CVE-2005-2873

    Last Modified: 16 Apr 2026

    The ipt_recent kernel module (ipt_recent.c) in Linux kernel 2.6.12 and earlier does not properly perform certain time tests when the jiffies value is greater than LONG_MAX, which can cause ipt_recent netfilter rules to block too early, a different vulnerability than CVE-2005-2872.

    Published: 9 May 2005
    5
    Medium

    CVE-2005-2872

    Last Modified: 16 Apr 2026

    The ipt_recent kernel module (ipt_recent.c) in Linux kernel before 2.6.12, when running on 64-bit processors such as AMD64, allows remote attackers to cause a denial of service (kernel panic) via certain attacks such as SSH brute force, which leads to memset calls using a length based on the u_int32_t type, acting on an array of unsigned long elements, a different vulnerability than CVE-2005-2873.

    Published: 9 May 2005
    5.1
    Medium

    CVE-2005-1476

    Last Modified: 16 Apr 2026

    Firefox 1.0.3 allows remote attackers to execute arbitrary Javascript in other domains by using an IFRAME and causing the browser to navigate to a previous javascript: URL, which can lead to arbitrary code execution when combined with CVE-2005-1477.

    Published: 8 May 2005
    5.1
    Medium

    CVE-2005-1477

    Last Modified: 16 Apr 2026

    The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities such as CVE-2005-1476, as demonstrated using a javascript: URL as the package icon and a cross-site scripting (XSS) attack on a vulnerable whitelist site.

    Published: 8 May 2005
    4.6
    Medium

    CVE-2005-1399

    Last Modified: 16 Apr 2026

    FreeBSD 4.6 to 4.11 and 5.x to 5.4 uses insecure default permissions for the /dev/iir device, which allows local users to execute restricted ioctl calls to read or modify data on hardware that is controlled by the iir driver.

    Published: 6 May 2005
    4.6
    Medium

    CVE-2005-1400

    Last Modified: 16 Apr 2026

    The i386_get_ldt system call in FreeBSD 4.7 to 4.11 and 5.x to 5.4 allows local users to access sensitive kernel memory via arguments with negative or very large values.

    Published: 6 May 2005
    7.5
    High

    CVE-2005-1471

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in RSA SecurID Web Agent 5, 5.2, and 5.3 allows remote attackers to execute arbitrary code via crafted chunked-encoding data.

    Published: 6 May 2005
    4.6
    Medium

    CVE-2005-1406

    Last Modified: 16 Apr 2026

    The kernel in FreeBSD 4.x to 4.11 and 5.x to 5.4 does not properly clear certain fixed-length buffers when copying variable-length data for use by applications, which could allow those applications to read previously used sensitive memory.

    Published: 6 May 2005
    5
    Medium

    CVE-2005-1453

    Last Modified: 16 Apr 2026

    fetchnews in leafnode 1.9.48 to 1.11.1 allows remote NNTP servers to cause a denial of service (crash) by closing the connection while fetchnews is reading (1) an article header or (2) an article body, which also prevents fetchnews from querying other servers.

    Published: 5 May 2005
    5
    Medium

    CVE-2005-0918

    Last Modified: 16 Apr 2026

    The NPSVG3.dll ActiveX control for Adobe SVG Viewer 3.02 and earlier, when running on Internet Explorer, allows remote attackers to determine the existence of arbitrary files by setting the src property to the target filename and using Javascript to determine if the web page immediately stops loading, which indicates whether the file exists or not.

    Published: 5 May 2005
    5
    Medium

    CVE-2005-1333

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the Bluetooth file and object exchange (OBEX) services in Mac OS X 10.3.9 allows remote attackers to read arbitrary files.

    Published: 4 May 2005
    7.2
    High

    CVE-2005-1335

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Mac OS X 10.3.9 allows local users to gain privileges via (1) chfn, (2) chpass, and (3) chsh, which "use external helper programs in an insecure manner."

    Published: 4 May 2005
    7.5
    High

    CVE-2005-1339

    Last Modified: 16 Apr 2026

    lukemftpd in Mac OS X 10.3.9 allows remote authenticated users to escape the chroot environment by logging in with their full name.

    Published: 4 May 2005
    7.5
    High

    CVE-2005-1340

    Last Modified: 16 Apr 2026

    The HTTP proxy service in Server Admin for Mac OS X 10.3.9 does not restrict access when it is enabled, which allows remote attackers to use the proxy.

    Published: 4 May 2005
    5.1
    Medium

    CVE-2005-1341

    Last Modified: 16 Apr 2026

    Apple Terminal 1.4.4 allows attackers to execute arbitrary commands via terminal escape sequences.

    Published: 4 May 2005
    7.5
    High

    CVE-2005-1342

    Last Modified: 16 Apr 2026

    The x-man-page: URI handler for Apple Terminal 1.4.4 in Mac OS X 10.3.9 does not cleanse terminal escape sequences, which allows remote attackers to execute arbitrary commands.

    Published: 4 May 2005
    4.6
    Medium

    CVE-2005-1338

    Last Modified: 16 Apr 2026

    Mac OS X 10.3.9, when using an LDAP server that does not use ldap_extended_operation, may store initial LDAP passwords for new accounts in plaintext.

    Published: 4 May 2005
    5.1
    Medium

    CVE-2005-1331

    Last Modified: 16 Apr 2026

    The AppleScript Editor in Mac OS X 10.3.9 does not properly display script code for an applescript: URI, which can result in code that is different than the actual code that would be run, which could allow remote attackers to trick users into executing malicious code via certain URI characters such as NULL, control characters, and homographs.

    Published: 4 May 2005
    7.5
    High

    CVE-2005-1332

    Last Modified: 16 Apr 2026

    Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default, which allows remote attackers to access files without the user being notified, and local users to access files via the default directory.

    Published: 4 May 2005
    4.6
    Medium

    CVE-2005-1336

    Last Modified: 16 Apr 2026

    Buffer overflow in the Foundation framework for Mac OS X 10.3.9 allows local users to execute arbitrary code via a long environment variable.

    Published: 4 May 2005
    7.5
    High

    CVE-2005-1337

    Last Modified: 16 Apr 2026

    Apple Help Viewer 2.0.7 and 3.0.0 in Mac OS X 10.3.9 allows remote attackers to read and execute arbitrary scrpts with less restrictive privileges via a help:// URI.

    Published: 4 May 2005
    7.2
    High

    CVE-2005-0594

    Last Modified: 16 Apr 2026

    Buffer overflow in the Netinfo Setup Tool (NeST) allows local users to execute arbitrary code.

    Published: 4 May 2005
    4.9
    Medium

    CVE-2005-1330

    Last Modified: 16 Apr 2026

    AppKit in Mac OS X 10.3.9 allows attackers to cause a denial of service (Cocoa application crash) via a malformed TIFF image that causes the NXSeek to use an incorrect offset, leading to an unhandled exception.

    Published: 4 May 2005
    5
    Medium

    CVE-2005-1456

    Last Modified: 16 Apr 2026

    Multiple unknown vulnerabilities in the (1) DHCP and (2) Telnet dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (abort).

    Published: 4 May 2005