CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2005-3109

    Last Modified: 16 Apr 2026

    The HFS and HFS+ (hfsplus) modules in Linux 2.6 allow attackers to cause a denial of service (oops) by using hfsplus to mount a filesystem that is not hfsplus.

    Published: 1 May 2005
    7.5
    High

    CVE-2005-1062

    Last Modified: 16 Apr 2026

    The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote attackers to quickly obtain passwords that are 5 characters or less via brute force methods.

    Published: 29 Apr 2005
    5
    Medium

    CVE-2005-1063

    Last Modified: 16 Apr 2026

    The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote attackers to cause a denial of service (CPU consumption) via certain attacks that force the product to "compute unexpected conditions" and "perform cryptographic operations."

    Published: 29 Apr 2005
    7.5
    High

    CVE-2005-1349

    Last Modified: 16 Apr 2026

    Buffer overflow in Convert-UUlib (Convert::UUlib) before 1.051 allows remote attackers to execute arbitrary code via a malformed parameter to a read operation.

    Published: 28 Apr 2005
    5
    Medium

    CVE-2005-1350

    Last Modified: 16 Apr 2026

    The ad.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.

    Published: 28 Apr 2005
    7.5
    High

    CVE-2005-1351

    Last Modified: 16 Apr 2026

    The ad.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.

    Published: 28 Apr 2005
    5
    Medium

    CVE-2005-1355

    Last Modified: 16 Apr 2026

    includer.cgi in The Includer allows remote attackers to read arbitrary files via a full pathname in the argument, a similar vulnerability to CVE-2005-0801.

    Published: 28 Apr 2005
    4.3
    Medium

    CVE-2005-1356

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in includer.cgi script in The Includer allows remote attackers to inject arbitrary web script or HTML via the argument.

    Published: 28 Apr 2005
    5
    Medium

    CVE-2005-1357

    Last Modified: 16 Apr 2026

    text.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.

    Published: 28 Apr 2005
    7.5
    High

    CVE-2005-1358

    Last Modified: 16 Apr 2026

    text.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.

    Published: 28 Apr 2005
    4.3
    Medium

    CVE-2005-1359

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in text.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.

    Published: 28 Apr 2005
    7.5
    High

    CVE-2005-1360

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in error.php in GrayCMS 1.1 allows remote attackers to execute arbitrary PHP code by modifying the path_prefix parameter to reference a URL on a remote web server that contains the code.

    Published: 28 Apr 2005
    2.6
    Low

    CVE-2005-1346

    Last Modified: 16 Apr 2026

    Multiple Symantec AntiVirus products, including Norton AntiVirus 2005 11.0.0, Web Security Web Security 3.0.1.72, Mail Security for SMTP 4.0.5.66, AntiVirus Scan Engine 4.3.7.27, SAV/Filter for Domino NT 3.1.1.87, and Mail Security for Exchange 4.5.4.743, when running on Windows, allows remote attackers to cause a denial of service (component crash) and avoid detection via a crafted RAR file.

    Published: 28 Apr 2005
    2.6
    Low

    CVE-2005-1347

    Last Modified: 16 Apr 2026

    ** UNVERIFIABLE ** NOTE: this issue describes a problem that can not be independently verified as of 20050421. Adobe Acrobat reader (AcroRd32.exe) 6.0 and earlier allows remote attackers to cause a denial of service ("Invalid-ID-Handle-Error" error) and modify memory beginning at a particular address, possibly allowing the execution of arbitrary code, via a crafted PDF file. NOTE: the vendor has stated that the reporter refused to provide sufficient details to confirm the issue. In addition, due to the lack of details in the original advisory, an independent verification is not possible. Finally, the reliability of the original reporter is unknown. This item has only been assigned a CVE identifier for tracking purposes, and to serve as a concrete example of the newly defined UNVERIFIABLE and PRERELEASE content decisions in CVE, which must be discussed by the Editorial Board. Without additional details or independent verification by reliable sources, it is highly likely that this item will be REJECTED.

    Published: 28 Apr 2005
    7.5
    High

    CVE-2005-1348

    Last Modified: 16 Apr 2026

    Buffer overflow in HTTPMail in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote attackers to execute arbitrary code via a long HTTP Authorization header.

    Published: 28 Apr 2005
    4.3
    Medium

    CVE-2005-1352

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the ad.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.

    Published: 28 Apr 2005
    5
    Medium

    CVE-2005-1353

    Last Modified: 16 Apr 2026

    The forum.pl script allows remote attackers to read arbitrary files via a full pathname in the argument.

    Published: 28 Apr 2005
    7.5
    High

    CVE-2005-1354

    Last Modified: 16 Apr 2026

    The forum.pl script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.

    Published: 28 Apr 2005
    7.5
    High

    CVE-2005-1361

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in MetaCart e-Shop 8.0 allow remote attackers to execute arbitrary SQL commands via the (1) intProdID parameter in product.asp or (2) strCatalog_NAME parameter to productsByCategory.asp.

    Published: 28 Apr 2005
    7.5
    High

    CVE-2005-1364

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in MetaBid Auctions allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password fields in logIn.asp, or (3) intAuctionID parameter to item.asp.

    Published: 28 Apr 2005
    7.5
    High

    CVE-2005-1363

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in MetaCart 2.0 for PayFlow allow remote attackers to execute arbitrary commands via (1) intCatalogID, (2) strSubCatalogID, or (3) strSubCatalog_NAME parameter to productsByCategory.asp, (4) curCatalogID, (5) strSubCatalog_NAME, (6) intCatalogID, or (7) page parameter to productsByCategory.asp or (8) intProdID parameter to product.asp.

    Published: 28 Apr 2005
    7.5
    High

    CVE-2005-1362

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in MetaCart 2.0 for Paypal allow remote attackers to execute arbitrary SQL commands via the (1) intProdID parameter to product.asp, (2) intCatalogID or (3) strSubCatalogID parameters to productsByCategory.asp, (4) chkText, (5) strText, (6) chkPrice, (7) intPrice, (8) chkCat, or (9) strCat parameters to searchAction.asp.

    Published: 28 Apr 2005
    5
    Medium

    CVE-2005-1431

    Last Modified: 16 Apr 2026

    The "record packet parsing" in GnuTLS 1.2 before 1.2.3 and 1.0 before 1.0.25 allows remote attackers to cause a denial of service, possibly related to padding bytes in gnutils_cipher.c.

    Published: 28 Apr 2005
    4.3
    Medium

    CVE-2005-1309

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in bBlog 0.7.4 allows remote attackers to inject arbitrary web script or HTML via the (1) entry title field or (2) comment body text.

    Published: 27 Apr 2005
    4.3
    Medium

    CVE-2005-1313

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Horde Passwd module before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.

    Published: 27 Apr 2005
    4.3
    Medium

    CVE-2005-1314

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Horde Kronolith module before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.

    Published: 27 Apr 2005
    4.3
    Medium

    CVE-2005-1315

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Horde Turba module before 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.

    Published: 27 Apr 2005
    4.3
    Medium

    CVE-2005-1316

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Horde Accounts module before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.

    Published: 27 Apr 2005
    4.3
    Medium

    CVE-2005-1318

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Horde Forwards E-Mail Forwarding Manager before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.

    Published: 27 Apr 2005
    4.3
    Medium

    CVE-2005-1322

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Horde Nag Task List Manager before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.

    Published: 27 Apr 2005
    7.5
    High

    CVE-2005-1323

    Last Modified: 16 Apr 2026

    Buffer overflow in NetFtpd for NetTerm 5.1.1 and earlier allows remote attackers to execute arbitrary code via a long USER command.

    Published: 27 Apr 2005
    4.3
    Medium

    CVE-2005-1324

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php for phpMyVisites allow remote attackers to inject arbitrary web script or HTML via the (1) part, (2) per, or (3) site parameters.

    Published: 27 Apr 2005
    5
    Medium

    CVE-2005-1325

    Last Modified: 16 Apr 2026

    set_lang.php in phpMyVisites 1.3 allows remote attackers to read and include arbitrary files via the mylang parameter.

    Published: 27 Apr 2005
    5
    Medium

    CVE-2005-1326

    Last Modified: 16 Apr 2026

    Buffer overflow in VooDoo cIRCle BOTNET before 1.0.33 allows remote authenticated attackers to cause a denial of service (client crash) via a crafted packet.

    Published: 27 Apr 2005
    4.3
    Medium

    CVE-2005-1327

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in pms.php for Woltlab Burning Board 2.3.1 PL2 and earlier allows remote attackers to inject arbitrary web script or HTML via the folderid parameter.

    Published: 27 Apr 2005
    7.5
    High

    CVE-2005-1344

    Last Modified: 16 Apr 2026

    Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.

    Published: 27 Apr 2005
    4.3
    Medium

    CVE-2005-1320

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Horde Mnemo Note Manager before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.

    Published: 27 Apr 2005
    4.3
    Medium

    CVE-2005-1321

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Horde Vacation module before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.

    Published: 27 Apr 2005
    5
    Medium

    CVE-2005-1329

    Last Modified: 16 Apr 2026

    owOfflineCC.asp in OneWorldStore allows remote attackers to obtain sensitive information by modifying the idOrder parameter.

    Published: 27 Apr 2005
    7.5
    High

    CVE-2004-1342

    Last Modified: 16 Apr 2026

    CVS 1.12 and earlier on Debian GNU/Linux, when using the repouid patch, allows remote attackers to bypass authentication via the pserver access method.

    Published: 27 Apr 2005
    4.3
    Medium

    CVE-2005-1311

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Yappa-NG before 2.3.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 27 Apr 2005
    4.3
    Medium

    CVE-2005-1319

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Horde IMP Webmail client before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.

    Published: 27 Apr 2005
    5
    Medium

    CVE-2005-1328

    Last Modified: 16 Apr 2026

    OneWorldStore allows remote attackers to cause a denial of service (application crash) via a direct request to owConnections/chksettings.asp.

    Published: 27 Apr 2005
    10
    Critical

    CVE-2005-1274

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the getIfHeader function in the WebDAV functionality in MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via an HTTP unlock request and a long "If" parameter.

    Published: 26 Apr 2005
    7.5
    High

    CVE-2005-1284

    Last Modified: 16 Apr 2026

    The addnew script in Argosoft Mail Server Pro 1.8.7.6 allows remote attackers to create arbitrary accounts, even if "Allow Creation of Accounts From the Web Interface" is disabled, via a direct HTTP POST request.

    Published: 26 Apr 2005
    4.3
    Medium

    CVE-2005-1290

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) u parameter to profile.php, (2) highlight parameter to viewtopic.php, or (3) forumname or forumdesc parameters to admin_forums.php.

    Published: 26 Apr 2005
    4.3
    Medium

    CVE-2005-1292

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in CartWIZ ASP Cart allow remote attackers to inject arbitrary web script or HTML via the idProduct parameter to (1) tellAFriend.asp or (2) addToWishlist.asp, redirect parameter to (3) access.asp or (4) login.asp, message parameter to (5) login.asp or (6) error.asp, or (7) sku or (8) name parameter to searchResults.asp.

    Published: 26 Apr 2005
    7.5
    High

    CVE-2005-1293

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in default.asp in StorePortal 2.63 allow remote attackers to execute arbitrary SQL commands via the (1) language, (2) bpic, (3) idcategory, (4) content, (5) keyword, or (6) idproduct parameter.

    Published: 26 Apr 2005
    7.5
    High

    CVE-2005-1302

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Confixx 3.08 and earlier allows remote attackers to execute arbitrary SQL commands via the "change user" field.

    Published: 26 Apr 2005
    5
    Medium

    CVE-2005-1305

    Last Modified: 16 Apr 2026

    The hyper.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.

    Published: 26 Apr 2005