CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2005-1465

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the NCP dissector in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (long loop).

    Published: 4 May 2005
    5
    Medium

    CVE-2005-1464

    Last Modified: 16 Apr 2026

    Multiple unknown vulnerabilities in the (1) KINK, (2) L2TP, (3) MGCP, (4) EIGRP, (5) DLSw, (6) MEGACO, (7) LMP, and (8) RSVP dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (infinite loop).

    Published: 4 May 2005
    5
    Medium

    CVE-2005-1457

    Last Modified: 16 Apr 2026

    Multiple unknown vulnerabilities in the (1) AIM, (2) LDAP, (3) FibreChannel, (4) GSM_MAP, (5) SRVLOC, and (6) NTLMSSP dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash).

    Published: 4 May 2005
    5
    Medium

    CVE-2005-1468

    Last Modified: 16 Apr 2026

    Multiple unknown vulnerabilities in the (1) WSP, (2) Q.931, (3) H.245, (4) KINK, (5) MGCP, (6) RPC, (7) SMBMailslot, and (8) SMB NETLOGON dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash) via unknown vectors that lead to a null dereference.

    Published: 4 May 2005
    5
    Medium

    CVE-2005-1458

    Last Modified: 16 Apr 2026

    Multiple unknown "other problems" in the KINK dissector in Ethereal before 0.10.11 have unknown impact and attack vectors.

    Published: 4 May 2005
    7.5
    High

    CVE-2005-1454

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via (1) group_membership_query, (2) simul_count_query, or (3) simul_verify_query configuration entries.

    Published: 4 May 2005
    7.5
    High

    CVE-2005-1455

    Last Modified: 16 Apr 2026

    Buffer overflow in the sql_escape_func function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote attackers to cause a denial of service (crash).

    Published: 4 May 2005
    5
    Medium

    CVE-2005-1459

    Last Modified: 16 Apr 2026

    Multiple unknown vulnerabilities in the (1) WSP, (2) BER, (3) SMB, (4) NDPS, (5) IAX2, (6) RADIUS, (7) TCAP, (8) MRDISC, (9) 802.3 Slow, (10) SMBMailslot, or (11) SMB PIPE dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (assert error).

    Published: 4 May 2005
    5
    Medium

    CVE-2005-1460

    Last Modified: 16 Apr 2026

    Multiple unknown dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (assert error) via an invalid protocol tree item length.

    Published: 4 May 2005
    7.5
    High

    CVE-2005-1461

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the (1) SIP, (2) CMIP, (3) CMP, (4) CMS, (5) CRMF, (6) ESS, (7) OCSP, (8) X.509, (9) ISIS, (10) DISTCC, (11) FCELS, (12) Q.931, (13) NCP, (14) TCAP, (15) ISUP, (16) MEGACO, (17) PKIX1Explitit, (18) PKIX_Qualified, (19) Presentation dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code.

    Published: 4 May 2005
    7.5
    High

    CVE-2005-1462

    Last Modified: 16 Apr 2026

    Double free vulnerability in the ICEP dissector in Ethereal before 0.10.11 may allow remote attackers to execute arbitrary code.

    Published: 4 May 2005
    7.5
    High

    CVE-2005-1463

    Last Modified: 16 Apr 2026

    Multiple format string vulnerabilities in the (1) DHCP and (2) ANSI A dissectors in Ethereal before 0.10.11 may allow remote attackers to execute arbitrary code.

    Published: 4 May 2005
    5
    Medium

    CVE-2005-1466

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the DICOM dissector in Ethereal before 0.10.11 allows remote attackers to cause a denial of service (large memory allocation) via unknown vectors.

    Published: 4 May 2005
    5
    Medium

    CVE-2005-1467

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the NDPS dissector in Ethereal before 0.10.11 allows remote attackers to cause a denial of service (memory exhaustion) via unknown vectors.

    Published: 4 May 2005
    5
    Medium

    CVE-2005-1469

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the GSM dissector in Ethereal before 0.10.11 allows remote attackers to cause the dissector to access an invalid pointer.

    Published: 4 May 2005
    5
    Medium

    CVE-2005-1470

    Last Modified: 16 Apr 2026

    Multiple unknown vulnerabilities in the (1) TZSP, (2) MGCP, (3) ISUP, (4) SMB, or (5) Bittorrent dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (segmentation fault) via unknown vectors.

    Published: 4 May 2005
    7.5
    High

    CVE-2005-1825

    Last Modified: 16 Apr 2026

    Multiple stack-based buffer overflows in the nvd_exec function in HP Radia Notify Daemon 3.1.2.0 (formerly by Novadigm), and other versions including 2.x, 3.x, and 4.x, allows remote attackers to execute arbitrary code via a command with crafted parameters to a RADEXECD process.

    Published: 3 May 2005
    7.2
    High

    CVE-2005-1343

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the VPN daemon (vpnd) for Mac OS X before 10.3.9 allows local users to execute arbitrary code via a long -i (Server_id) argument.

    Published: 3 May 2005
    7.5
    High

    CVE-2005-1401

    Last Modified: 16 Apr 2026

    Format string vulnerability in the client for Mtp-Target 1.2.2 and earlier allows remote attackers to execute arbitrary code via game messages or other text.

    Published: 3 May 2005
    6.8
    Medium

    CVE-2005-1403

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in JustWilliam's Amazon Webstore 04050100 allow remote attackers to inject arbitrary web script or HTML via the (1) image parameter to closeup.php, the (2) currentIsExpanded or (3) searchFor parameters to index.php, (4) the currentNumber parameter to software_CAD_Technical_60002_uk.htm, or (5) a cookie.

    Published: 3 May 2005
    5
    Medium

    CVE-2005-1404

    Last Modified: 16 Apr 2026

    MyPHP Forum 1.0 allows remote attackers to spoof the username by modifying the (1) nbuser parameter to post.php or (2) sender parameter to privmsg.php.

    Published: 3 May 2005
    4.6
    Medium

    CVE-2005-1411

    Last Modified: 16 Apr 2026

    Cybration ICUII 7.0 stores passwords in plaintext in the world-readable icuii.ini file, which allows local users to gain privileges.

    Published: 3 May 2005
    5
    Medium

    CVE-2005-1416

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in 04WebServer 1.81 allows remote attackers to read files outside of the web root but within the installation folder.

    Published: 3 May 2005
    4.6
    Medium

    CVE-2005-1418

    Last Modified: 16 Apr 2026

    NetLeaf Limited NotJustBrowsing 1.0.3 stores the View Lock Password in plaintext in the notjustbrowsing.prf file, which allows local users to gain privileges.

    Published: 3 May 2005
    7.5
    High

    CVE-2005-1419

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the admin login panel for Ocean12 Mailing List Manager 1.06 allows remote attackers to execute arbitrary SQL commands via the Admin_id parameter.

    Published: 3 May 2005
    6.4
    Medium

    CVE-2005-1423

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the mail program in 602LAN SUITE 2004.0.05.0413 allows remote attackers to cause a denial of service and determine the presence of arbitrary files via .. sequences in the A parameter.

    Published: 3 May 2005
    2.1
    Low

    CVE-2005-1424

    Last Modified: 16 Apr 2026

    StumbleInside GoText 1.01 stores sensitive username, mail address,and phone number information in plaintext in the GoText.bin file, which allows local users to obtain that information.

    Published: 3 May 2005
    5
    Medium

    CVE-2005-1425

    Last Modified: 16 Apr 2026

    Uapplication Uguestbook 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mdb-database/guestbook.mdb.

    Published: 3 May 2005
    5
    Medium

    CVE-2005-1426

    Last Modified: 16 Apr 2026

    Uapplication Ublog Reload stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mdb-database/blog.mdb (aka mdb-database/blog.msb).

    Published: 3 May 2005
    7.5
    High

    CVE-2005-1427

    Last Modified: 16 Apr 2026

    Uapplication Uphotogallery stores the database under the web document root, which allows remote attackers to obtain sensitive information via a direct request to uphotogallery.mdb.

    Published: 3 May 2005
    7.5
    High

    CVE-2005-1428

    Last Modified: 16 Apr 2026

    edit_image.asp in Uapplication Uphotogallery allows remote attackers to upload arbitrary files.

    Published: 3 May 2005
    4.6
    Medium

    CVE-2005-1433

    Last Modified: 16 Apr 2026

    Multiple unknown vulnjerabilities HP OpenView Event Correlation Services (OV ECS) 3.32 and 3.33 allow attackers to cause a denial of service or execute arbitrary code.

    Published: 3 May 2005
    7.5
    High

    CVE-2005-1434

    Last Modified: 16 Apr 2026

    Multiple unknown vulnerabilities in OpenView Network Node Manager (OV NNM) 6.2, 6.4, 7.01, and 7.50 allow attackers to cause a denial of service or execute arbitrary code.

    Published: 3 May 2005
    7.5
    High

    CVE-2005-1435

    Last Modified: 16 Apr 2026

    Open WebMail (OWM) before 2.51 20050430 allows remote authenticated users to execute arbitrary commands via shell metacharacters in a filename.

    Published: 3 May 2005
    7.5
    High

    CVE-2005-1437

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in osTicket allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to admin.php or (2) cat parameter to view.php.

    Published: 3 May 2005
    7.5
    High

    CVE-2005-1438

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in main.php in osTicket allows remote attackers to execute arbitrary PHP code via the include_dir parameter.

    Published: 3 May 2005
    4.6
    Medium

    CVE-2005-1442

    Last Modified: 16 Apr 2026

    Buffer overflow in the Lotus Notes client for Domino 6.5 before 6.5.4 and 6.0 before 6.0.5 allows local users to cause a denial of service (client crash) and possibly execute arbitrary code via the NOTES.INI file.

    Published: 3 May 2005
    6.8
    Medium

    CVE-2005-1443

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php for Invision Power Board (IPB) 2.0.3 and 2.1 Alpha 2 allows remote attackers to inject arbitrary web script or HTML via the (1) act, (2) Members, (3) calendar, or (4) HID parameters.

    Published: 3 May 2005
    6.8
    Medium

    CVE-2005-1444

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in SitePanel 2.6.1 and earlier (SitePanel2) allows remote attackers to inject arbitrary web script or HTML via (1) the v, show, or sec_name parameters to main.php, (2) the inadmin, newsev, or postid parameters to 5.php, or (3) the id parameter to 0.php.

    Published: 3 May 2005
    6.4
    Medium

    CVE-2005-1445

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in SitePanel 2.6.1 and earlier (SitePanel2) allows remote attackers to (1) delete arbitrary files via the id parameter in a rmattach action to 5.php, or (2) read arbitrary files via the lang parameter to index.php.

    Published: 3 May 2005
    7.5
    High

    CVE-2005-1446

    Last Modified: 16 Apr 2026

    SitePanel 2.6.1 and earlier (SitePanel2) allows remote attackers to upload and execute arbitrary files such as PHP scripts via an attachment to a trouble ticket.

    Published: 3 May 2005
    7.5
    High

    CVE-2005-1450

    Last Modified: 16 Apr 2026

    Unknown vulnerability in "the function used to validate path-names for uploading media" in Serendipity before 0.8 has unknown impact.

    Published: 3 May 2005
    7.5
    High

    CVE-2005-1451

    Last Modified: 16 Apr 2026

    The media manager in Serendipity before 0.8 allows remote attackers to upload and execute arbitrary (1) .php or (2) .shtml files.

    Published: 3 May 2005
    10
    Critical

    CVE-2005-1452

    Last Modified: 16 Apr 2026

    Serendipity before 0.8 allows Chief users to "hide plugins installed by other users."

    Published: 3 May 2005
    2.1
    Low

    CVE-2005-1405

    Last Modified: 16 Apr 2026

    HTTP response splitting vulnerability in the @SetHTTPHeader function in Lotus Domino 6.5.x before 6.5.4 and 6.0.x before 6.0.5 allows attackers to poison the web cache via malicious applications.

    Published: 3 May 2005
    7.5
    High

    CVE-2005-1413

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in enVivo!CMS allow remote attackers to execute arbitrary SQL commands and gain privileges via the (1) username or (2) password parameters to admin_login.asp, or the (3) searchstring and possibly (4) ID parameters to default.asp.

    Published: 3 May 2005
    10
    Critical

    CVE-2005-1415

    Last Modified: 16 Apr 2026

    Buffer overflow in GlobalSCAPE Secure FTP Server 3.0.2 allows remote authenticated users to execute arbitrary code via a long FTP command.

    Published: 3 May 2005
    5
    Medium

    CVE-2005-1421

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to read arbitrary files via ".." (dot dot) sequences in an HTTP request.

    Published: 3 May 2005
    7.5
    High

    CVE-2005-1422

    Last Modified: 16 Apr 2026

    Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to conduct administrator operations and cause a denial of service (server or camera shutdown) via a direct request to admin.html.

    Published: 3 May 2005
    3.6
    Low

    CVE-2005-1430

    Last Modified: 16 Apr 2026

    Mac OS X 10.3.x and earlier uses insecure permissions for a pseudo terminal tty (pty) that is managed by a non-setuid program, which allows local users to read or modify sessions of other users.

    Published: 3 May 2005