CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2005-1439

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in attachments.php in osTicket allows remote attackers to read arbitrary files via .. sequences in the file parameter.

    Published: 3 May 2005
    5
    Medium

    CVE-2005-1441

    Last Modified: 16 Apr 2026

    Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the Notes protocol (NRPC).

    Published: 3 May 2005
    10
    Critical

    CVE-2005-1449

    Last Modified: 16 Apr 2026

    Unknown vulnerability in serendipity_config_local.inc.php for Serendipity before 0.8 has unknown impact.

    Published: 3 May 2005
    5
    Medium

    CVE-2005-1402

    Last Modified: 16 Apr 2026

    Integer signedness error in certain older versions of the NeL library, as used in Mtp-Target 1.2.2 and earlier, and possibly other products, allows remote attackers to cause a denial of service (memory consumption or server crash) via a negative value in a STLport call, which is not caught by a signed comparison.

    Published: 3 May 2005
    4.6
    Medium

    CVE-2005-1407

    Last Modified: 16 Apr 2026

    Skype for Windows 1.2.0.0 to 1.2.0.46 allows local users to bypass the identity check for an authorized application, then call arbitrary Skype API functions by modifying or replacing that application.

    Published: 3 May 2005
    4.6
    Medium

    CVE-2005-1414

    Last Modified: 16 Apr 2026

    ExoticSoft FilePocket 1.2 stores sensitive proxy information, including proxy passwords, in plaintext in the registry, which allows local users to gain privileges.

    Published: 3 May 2005
    6.8
    Medium

    CVE-2005-1436

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in osTicket allow remote attackers to inject arbitrary web script or HTML via (1) the t parameter to view.php, (2) the osticket_title parameter to header.php, (3) the em parameter to admin_login.php, (4) the e parameter to user_login.php, (5) the err parameter to open_submit.php, or (6) the name and subject fields when adding a ticket.

    Published: 3 May 2005
    6.8
    Medium

    CVE-2005-1440

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) various parameters to basket.php, (2) the nickname, email, topic, and message fields in forum.php, as demonstrated using forum_new_thread.php and forum_thread.php, (3) the page parameter to page.php, (4) category_id and item_id parameters to reviews.php, (5) the category_id parameter to product_details.php, (6) the category_id or search_string parameters to products.php, or (7) the rp or page parameters to news_view.php.

    Published: 3 May 2005
    6.8
    Medium

    CVE-2005-1448

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the BBCode plugin for Serendipity before 0.8 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 3 May 2005
    7.5
    High

    CVE-2005-1826

    Last Modified: 16 Apr 2026

    Buffer overflow in HP Radia Notify Daemon 3.1.0.0 (formerly by Novadigm), and other versions including 2.x, 3.x, and 4.x, allows remote attackers to execute arbitrary code via a long file extension.

    Published: 3 May 2005
    7.5
    High

    CVE-2005-0157

    Last Modified: 16 Apr 2026

    The confirm add-on in SmartList 3.15 and earlier allows attackers to subscribe arbitrary e-mail addresses by using a valid cookie that specifies an address other than the address for which the cookie was assigned.

    Published: 3 May 2005
    4.6
    Medium

    CVE-2005-0106

    Last Modified: 16 Apr 2026

    SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entropy if a source is not set in the EGD_PATH variable, which allows local users to reduce the cryptographic strength of certain operations by modifying the file.

    Published: 3 May 2005
    7.5
    High

    CVE-2005-1412

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in verify.asp for Ecomm Professional Guestbook 3.x allows remote attackers to execute arbitrary SQL commands via the AdminPWD parameter.

    Published: 3 May 2005
    7.5
    High

    CVE-2005-1417

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in MaxWebPortal 2.x, 1.35, and other versions allow remote attackers to execute arbitrary SQL commands via (1) article_popular.asp, (2) arguments to dl_popular.asp, (3) arguments to links_popular.asp, (4) arguments to pic_popular.asp, (5) article_rate.asp, (6) dl_rate.asp, (7) links_rate.asp, (8) pic_rates.asp, (9) article_toprated.asp, (10) dl_toprated.asp, (11) links_toprated.asp, (12) arguments to pic_toprated.asp, or (13) the TOPIC_ID or Forum_ID parameters to custom_link.asp.

    Published: 3 May 2005
    5
    Medium

    CVE-2005-1420

    Last Modified: 16 Apr 2026

    Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to determine the full pathname of the server via a request for an invalid page, as demonstrated using "%20" (hex-encoded space).

    Published: 3 May 2005
    7.5
    High

    CVE-2005-1429

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in login.asp in WWWguestbook 1.1 allows remote attackers to execute arbitrary SQL commands via the password parameter.

    Published: 3 May 2005
    7.5
    High

    CVE-2005-1447

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in main.php in SitePanel 2.6.1 and earlier (SitePanel2) allows remote attackers to execute arbitrary PHP code via the p parameter.

    Published: 3 May 2005
    1.2
    Low

    CVE-2005-1368

    Last Modified: 16 Apr 2026

    The key_user_lookup function in security/keys/key.c in Linux kernel 2.6.10 to 2.6.11.8 may allow attackers to cause a denial of service (oops) via SMP.

    Published: 2 May 2005
    4.6
    Medium

    CVE-2005-1372

    Last Modified: 16 Apr 2026

    nvstatsmngr.exe process in BakBone NetVault 7.1 does not properly drop privileges before opening files, which allows local users to gain privileges via the Help menu.

    Published: 2 May 2005
    7.5
    High

    CVE-2005-1373

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in Dream4 Koobi CMS 4.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) q or (2) p parameters.

    Published: 2 May 2005
    6.8
    Medium

    CVE-2005-1374

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to inject arbitrary web script or HTML via (1) exercise_result.php, (2) exercice_submit.php, (3) agenda.php, (4) learningPathList.php, (5) learningPathAdmin.php, (6) learningPath.php, (7) userLog.php, (8) tool parameter to toolaccess_details.php, (9) data parameter to user_access_details.php, or (10) coursePath parameter to myagenda.php.

    Published: 2 May 2005
    7.5
    High

    CVE-2005-1375

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to execute arbitrary SQL commands via (1) learningPath.php, (2) learningPathAdmin.php, (3) learnPath_details.php, (4) modules_pool.php, (5) module.php, (6) uInfo parameter in userInfo.php, or (7) exo_id parameter to exercises_details.php.

    Published: 2 May 2005
    7.5
    High

    CVE-2005-1376

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in (1) document.php or (2) insertMyDoc.php in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote project administrators to upload arbitrary files.

    Published: 2 May 2005
    6.8
    Medium

    CVE-2005-1380

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in BEA Admin Console 8.1 allows remote attackers to execute arbitrary web script or HTML via the server parameter to a JndiFramesetAction action.

    Published: 2 May 2005
    5
    Medium

    CVE-2005-1382

    Last Modified: 16 Apr 2026

    The webcacheadmin module in Oracle Webcache 9i allows remote attackers to corrupt arbitrary files via a full pathname in the cache_dump_file parameter.

    Published: 2 May 2005
    7.5
    High

    CVE-2005-1383

    Last Modified: 16 Apr 2026

    The OHS component 1.0.2 through 10.x, when UseWebcacheIP is disabled, in Oracle Application Server allows remote attackers to bypass HTTP Server mod_access restrictions via a request to the webcache TCP port 7778.

    Published: 2 May 2005
    7.5
    High

    CVE-2005-1384

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in phpCoin 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to index.php, (2) phpcoinsessid parameter to login.php, (3) id, (4) dtopic_id, or (5) dcat_id to mod.php.

    Published: 2 May 2005
    2.6
    Low

    CVE-2005-1385

    Last Modified: 16 Apr 2026

    Safari 1.3 allows remote attackers to cause a denial of service (application crash) via a long https URL that triggers a NULL pointer dereference.

    Published: 2 May 2005
    7.5
    High

    CVE-2005-1391

    Last Modified: 16 Apr 2026

    Buffer overflow in the add_port function in APSIS Pound 1.8.2 and earlier allows remote attackers to execute arbitrary code via a long Host HTTP header.

    Published: 2 May 2005
    4.6
    Medium

    CVE-2005-1392

    Last Modified: 16 Apr 2026

    The SQL install script in phpMyAdmin 2.6.2 is created with world-readable permissions, which allows local users to obtain the initial database password by reading the script.

    Published: 2 May 2005
    4.6
    Medium

    CVE-2005-1393

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in ArcGIS for ESRI ArcInfo Workstation 9.0 allow local users to execute arbitrary code via long command line arguments to (1) asmaster, (2) asuser, (3) asutility, (4) se, or (5) asrecovery.

    Published: 2 May 2005
    7.2
    High

    CVE-2005-1394

    Last Modified: 16 Apr 2026

    Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain privileges via format string specifiers in the ARCHOME environment variable to (1) wservice or (2) lockmgr.

    Published: 2 May 2005
    7.2
    High

    CVE-2005-1395

    Last Modified: 16 Apr 2026

    Buffer overflow in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier may allow local users to gain privileges via a long (1) XAPPLRESLANGPATH or (2) XAPPLRESDIR environment variable, or (3) command line argument.

    Published: 2 May 2005
    4.3
    Medium

    CVE-2005-1388

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in SURVIVOR before 0.9.6 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 2 May 2005
    5
    Medium

    CVE-2005-1398

    Last Modified: 16 Apr 2026

    phpcart.php in PHPCart 3.2 allows remote attackers to change product price information by modifying the (1) price or (2) postage parameters. NOTE: it was later reported that 3.4 through 4.6.4 are also affected.

    Published: 2 May 2005
    7.2
    High

    CVE-2005-1371

    Last Modified: 16 Apr 2026

    BPFTPServer service in BulletProof FTP Server 2.4.0.31 does not properly drop privileges before opening files through the Help menu, which allows local users to gain privileges.

    Published: 2 May 2005
    7.5
    High

    CVE-2005-1378

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in posting_notes.php in the notes module for phpBB allows remote attackers to execute arbitrary SQL commands via the p parameter, which is used in the $post_id variable, and other attack vectors.

    Published: 2 May 2005
    4.6
    Medium

    CVE-2005-1379

    Last Modified: 16 Apr 2026

    The LAM runtime environment package (lam-runtime-7.0.6-2mdk) on Mandrake Linux installs the mpi user without a password, which allows local users to gain privileges.

    Published: 2 May 2005
    6.8
    Medium

    CVE-2005-1381

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Oracle Webcache 9i allow remote attackers to inject arbitrary web script or HTML via the (1) cache_dump_file or (2) PartialPageErrorPage parameter.

    Published: 2 May 2005
    5
    Medium

    CVE-2005-1386

    Last Modified: 16 Apr 2026

    PHP-Nuke 7.6 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) ipban.php, (2) db.php, (3) lang-norwegian.php, (4) lang-indonesian.php, (5) lang-greek.php, (6) a request to Web_Links with the portuguese language (lang-portuguese.php), (7) a request to Web_Links with the indonesian language (lang-indonesian.php), (8) a request to the survey module with the indonesian language (lang-indonesian.php), (9) a request to the Reviews module with the portuguese language, or (10) a request to the Journal module with the portuguese language, which reveal the path in an error message.

    Published: 2 May 2005
    7.5
    High

    CVE-2005-1370

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Radia Management Agent (RMA) in HP OpenView Radia Management Portal (RMP) 1.x and 2.x allows remote attackers to execute arbitrary commands via unknown vectors.

    Published: 2 May 2005
    7.2
    High

    CVE-2005-1387

    Last Modified: 16 Apr 2026

    Cocktail 3.5.4 and possibly earlier in Mac OS X passes the administrative password on the command line to sudo in cleartext, which allows local users to gain sensitive information by running listing processes.

    Published: 2 May 2005
    7.5
    High

    CVE-2005-1397

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search.php for PHP-Calendar before 0.10.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

    Published: 2 May 2005
    1.2
    Low

    CVE-2005-1396

    Last Modified: 16 Apr 2026

    Race condition in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier allows local users to write to arbitrary files via a symlink attack on the ce_edit_log temporary file.

    Published: 2 May 2005
    Unknown

    CVE-2005-1390

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-0174. Reason: This candidate is a duplicate of CVE-2005-0174. Notes: All CVE users should reference CVE-2005-0174 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 2 May 2005
    Unknown

    CVE-2005-1389

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-0175. Reason: This candidate is a duplicate of CVE-2005-0175. Notes: All CVE users should reference CVE-2005-0175 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 2 May 2005
    2.1
    Low

    CVE-2005-1369

    Last Modified: 16 Apr 2026

    The (1) it87 and (2) via686a drivers in I2C for Linux 2.6.x before 2.6.11.8, and 2.6.12 before 2.6.12-rc2, create the sysfs "alarms" file with write permissions, which allows local users to cause a denial of service (CPU consumption) by attempting to write to the file, which does not have an associated store function.

    Published: 2 May 2005
    7.5
    High

    CVE-2005-1377

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to execute arbitrary PHP code via unknown vectors.

    Published: 2 May 2005
    2.1
    Low

    CVE-2005-1410

    Last Modified: 16 Apr 2026

    The tsearch2 module in PostgreSQL 7.4 through 8.0.x declares the (1) dex_init, (2) snb_en_init, (3) snb_ru_init, (4) spell_init, and (5) syn_init functions as "internal" even when they do not take an internal argument, which allows attackers to cause a denial of service (application crash) and possibly have other impacts via SQL commands that call other functions that accept internal arguments.

    Published: 2 May 2005
    7.5
    High

    CVE-2005-1409

    Last Modified: 16 Apr 2026

    PostgreSQL 7.3.x through 8.0.x gives public EXECUTE access to certain character conversion functions, which allows unprivileged users to call those functions with malicious values, with unknown impact, aka the "Character conversion vulnerability."

    Published: 2 May 2005