CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2005-1270

    Last Modified: 16 Apr 2026

    The (1) check_update.sh and (2) rkhunter script in Rootkit Hunter before 1.2.3-r1 create temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack.

    Published: 26 Apr 2005
    5
    Medium

    CVE-2005-1281

    Last Modified: 16 Apr 2026

    Ethereal 0.10.10 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of length 4.

    Published: 26 Apr 2005
    4.3
    Medium

    CVE-2005-1282

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Argosoft Mail Server Pro 1.8.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the src parameter in an IMG tag, (2) User settings, or (3) Address book input boxes in the webmail interface.

    Published: 26 Apr 2005
    1.2
    Low

    CVE-2005-1286

    Last Modified: 16 Apr 2026

    Unquoted Windows search path vulnerability in BitDefender 8 allows local users to prevent BitDefender from starting by creating a malicious C:\program.exe, possibly due to the lack of quoting of the full pathname when executing a process.

    Published: 26 Apr 2005
    7.5
    High

    CVE-2005-1288

    Last Modified: 16 Apr 2026

    inc_login_check.asp ACS Blog 0.8 through 1.1.3 allows remote attackers to gain administrator privileges via the "in" value in a cookie.

    Published: 26 Apr 2005
    7.5
    High

    CVE-2005-1289

    Last Modified: 16 Apr 2026

    index.cgi in E-Cart 2004 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) art and possibly (2) cat parameters.

    Published: 26 Apr 2005
    7.5
    High

    CVE-2005-1304

    Last Modified: 16 Apr 2026

    The citat.pl script allows remote attackers to execute arbitrary files via shell metacharacters in the argument.

    Published: 26 Apr 2005
    5
    Medium

    CVE-2005-1278

    Last Modified: 16 Apr 2026

    The isis_print function, as called by isoclns_print, in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a zero length, as demonstrated using a GRE packet.

    Published: 26 Apr 2005
    5
    Medium

    CVE-2005-1279

    Last Modified: 16 Apr 2026

    tcpdump 3.8.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted (1) BGP packet, which is not properly handled by RT_ROUTING_INFO, or (2) LDP packet, which is not properly handled by the ldp_print function.

    Published: 26 Apr 2005
    5
    Medium

    CVE-2005-1280

    Last Modified: 16 Apr 2026

    The rsvp_print function in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of length 4.

    Published: 26 Apr 2005
    6.8
    Medium

    CVE-2005-1297

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the include.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.

    Published: 25 Apr 2005
    7.5
    High

    CVE-2005-1298

    Last Modified: 16 Apr 2026

    The inserter.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.

    Published: 25 Apr 2005
    10
    Critical

    CVE-2005-1299

    Last Modified: 16 Apr 2026

    The inserter.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.

    Published: 25 Apr 2005
    6.8
    Medium

    CVE-2005-1300

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the inserter.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.

    Published: 25 Apr 2005
    6.8
    Medium

    CVE-2005-1317

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Horde Chora module before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.

    Published: 25 Apr 2005
    5
    Medium

    CVE-2005-1192

    Last Modified: 16 Apr 2026

    Unknown vulnerability in HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23, when running TCP/IP on IPv4, allows remote attackers to cause a denial of service via certain packets, related to the PMTU, a different vulnerability than CVE-2004-1060.

    Published: 25 Apr 2005
    7.5
    High

    CVE-2005-1296

    Last Modified: 16 Apr 2026

    include.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.

    Published: 25 Apr 2005
    7.5
    High

    CVE-2005-1295

    Last Modified: 16 Apr 2026

    include.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.

    Published: 25 Apr 2005
    10
    Critical

    CVE-2005-0684

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long file parameter after a percent ("%") sign or (2) a long Lock-Token string to the WebDAV functionality, which is not properly handled by the getLockTokenHeader function in WDVHandler_CommonUtils.c.

    Published: 25 Apr 2005
    5
    Medium

    CVE-2005-1739

    Last Modified: 16 Apr 2026

    The XWD Decoder in ImageMagick before 6.2.2.3, and GraphicsMagick before 1.1.6-r1, allows remote attackers to cause a denial of service (infinite loop) via an image with a zero color mask.

    Published: 25 Apr 2005
    4.3
    Medium

    CVE-2005-1231

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the NewTerm function in GlossaryModel.php in JAWS 0.4 allows remote attackers to inject arbitrary web script or HTML via the (1) term or (2) description.

    Published: 24 Apr 2005
    7.5
    High

    CVE-2005-1237

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in news.php in FlexPHPNews 0.0.3 allows remote attackers to execute arbitrary SQL commands via the newsid parameter.

    Published: 24 Apr 2005
    7.5
    High

    CVE-2005-1238

    Last Modified: 16 Apr 2026

    By design, the built-in FTP server for iSeries AS/400 systems does not support a restricted document root, which allows attackers to read or write arbitrary files, including sensitive QSYS databases, via a full pathname in a GET or PUT request.

    Published: 24 Apr 2005
    5
    Medium

    CVE-2005-1239

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the third party tool from Raz-Lee, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request.

    Published: 24 Apr 2005
    5
    Medium

    CVE-2005-1243

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the third party tool from SafeStone, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request.

    Published: 24 Apr 2005
    4.3
    Medium

    CVE-2005-1245

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.2, when using HTML Tidy ($wgUseTidy), allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 24 Apr 2005
    10
    Critical

    CVE-2005-1246

    Last Modified: 16 Apr 2026

    Format string vulnerability in the snmppd_log function in snmppd_util.c for snmppd 0.4.5 and earlier may allow remote attackers to cause a denial of service or execute arbitrary code via format string specifiers that are not properly handled in a syslog call.

    Published: 24 Apr 2005
    5
    Medium

    CVE-2005-1235

    Last Modified: 16 Apr 2026

    auction_my_auctions.php in phpbb-Auction 1.2m and earlier allows remote attackers to obtain sensitive information via an invalid mode parameter, which leaks the full path in a PHP error message.

    Published: 24 Apr 2005
    5
    Medium

    CVE-2005-1242

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the third party tool from Bsafe, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request.

    Published: 24 Apr 2005
    7.5
    High

    CVE-2005-1312

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in Yappa-NG before 2.3.2 allows remote attackers to execute arbitrary PHP code via unknown vectors.

    Published: 24 Apr 2005
    7.5
    High

    CVE-2005-1232

    Last Modified: 16 Apr 2026

    Buffer overflow in Sun Java System Web Proxy Server (aka Sun ONE Proxy Server) 3.6 SP6 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 24 Apr 2005
    7.5
    High

    CVE-2005-1236

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in DUware DUportal 3.1.2 and 3.1.2 SQL allow remote attackers to execute arbitrary SQL commands via the (1) iChannel parameter to channel.asp or search.asp, (2) iData parameter to detail.asp or inc_rating.asp, (3) iCat parameter to detail.asp or type.asp, (4) DAT_PARENT parameter to inc_poll_voting.asp, or (5) iRate parameter to inc_rating.asp, a different set of vulnerabilities than CVE-2005-1224.

    Published: 24 Apr 2005
    5
    Medium

    CVE-2005-1234

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via the (1) u parameter to auction_rating.php or (2) ar parameter to action_offer.php.

    Published: 24 Apr 2005
    7.2
    High

    CVE-2005-1294

    Last Modified: 16 Apr 2026

    The affix_sock_register in the Affix Bluetooth Protocol Stack for Linux might allow local users to gain privileges via a socket call with a negative protocol value, which is used as an array index.

    Published: 24 Apr 2005
    7.5
    High

    CVE-2005-1303

    Last Modified: 16 Apr 2026

    The citat.pl script allows remote attackers to read arbitrary files via a full pathname in the argument.

    Published: 24 Apr 2005
    7.8
    High

    CVE-2005-4886

    Last Modified: 11 Apr 2025

    The selinux_parse_skb_ipv6 function in security/selinux/hooks.c in the Linux kernel before 2.6.12-rc4 allows remote attackers to cause a denial of service (OOPS) via vectors associated with an incorrect call to the ipv6_skip_exthdr function.

    Published: 24 Apr 2005
    5
    Medium

    CVE-2005-1275

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a PNM file with a small colors value.

    Published: 24 Apr 2005
    7.5
    High

    CVE-2005-1291

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in CartWIZ ASP Cart allow remote attackers to execute arbitrary SQL commands via the idProduct parameter to (1) addToCart.asp or (2) productDetails.asp, the (3) priceFrom, (4) idCategory, or (5) priceTo parameter to searchResults.asp, or (6) the idParentCategory parameter to productCatalogSubCats.asp.

    Published: 23 Apr 2005
    7.5
    High

    CVE-2005-1310

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in bBlog 0.7.4 allows remote attackers to execute arbitrary SQL commands via the postid parameter.

    Published: 23 Apr 2005
    7.5
    High

    CVE-2005-1287

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in BK Forum 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to member.asp, (2) forum parameter to forum.asp, or (3) various parameters in register.asp.

    Published: 23 Apr 2005
    7.6
    High

    CVE-2005-0970

    Last Modified: 16 Apr 2026

    Mac OS X 10.3.9 and earlier allows users to install, create, and execute setuid/setgid scripts, contrary to the intended design, which may allow attackers to conduct unauthorized activities with escalated privileges via vulnerable scripts.

    Published: 22 Apr 2005
    7.5
    High

    CVE-2005-1220

    Last Modified: 16 Apr 2026

    Shoutbox SCRIPT 3.0.2 and earlier allows remote attackers to obtain sensitive information via a direct request to db/settings.dat, which displays usernames and password hashes.

    Published: 22 Apr 2005
    7.5
    High

    CVE-2005-1221

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in login.asp for Ecommerce-Carts EcommPro 3.0 allows remote attackers to execute arbitrary SQL commands via the password field.

    Published: 22 Apr 2005
    7.5
    High

    CVE-2005-1222

    Last Modified: 16 Apr 2026

    cat_for_gen.php in Annuaire Netref 4.2 allows remote attackers to execute arbitrary PHP code by setting the ad_direct parameter to reference cat_for_gen.php, then including the code in the m_for_racine parameter, which is then written to cat_for_gen.php.

    Published: 22 Apr 2005
    7.5
    High

    CVE-2005-1223

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Ocean12 Calendar manager 1.01 allow remote attackers to execute arbitrary SQL commands via the Admin_id field.

    Published: 22 Apr 2005
    5
    Medium

    CVE-2005-1230

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Yawcam 0.2.5 allows remote attackers to read arbitrary files via "..\" (dot dot backslash) sequences in a GET request.

    Published: 22 Apr 2005
    7.5
    High

    CVE-2005-1283

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in Argosoft Mail Server Pro 1.8.7.6 allow remote authenticated users to (1) read arbitrary files via the UIDL parameter to the msg script or (2) copy or move the user's .eml file to arbitrary locations via the delete script, a different vulnerability than CVE-2005-0367.

    Published: 22 Apr 2005
    6.8
    Medium

    CVE-2005-1285

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in thread.php in WoltLab Burning Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the hilight parameter.

    Published: 22 Apr 2005
    7.5
    High

    CVE-2005-1225

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Coppermine Photo Gallery 1.3.2 allows remote attackers to execute arbitrary SQL commands via the favs parameter to (1) init.inc.php or (2) zipdownload.php.

    Published: 22 Apr 2005
    7.5
    High

    CVE-2005-1226

    Last Modified: 16 Apr 2026

    Coppermine Photo Gallery 1.3.2 stores passwords in plaintext, which allows remote attackers to obtain sensitive information.

    Published: 22 Apr 2005