CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2005-0754

    Last Modified: 16 Apr 2026

    Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code.

    Published: 22 Apr 2005
    2.1
    Low

    CVE-2005-0975

    Last Modified: 16 Apr 2026

    Integer signedness error in the parse_machfile function in the mach-o loader (mach_loader.c) for the Darwin Kernel as used in Mac OS X 10.3.7, and other versions before 10.3.9, allows local users to cause a denial of service (CPU consumption) via a crafted mach-o header.

    Published: 22 Apr 2005
    7.5
    High

    CVE-2005-1224

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) nChannel parameter to default.asp, cat.asp, or detail.asp, (2) the iChannel parameter to search.asp, default.asp, result.asp, cat.asp, or detail.asp (3) the iCat parameter to cat.asp or detail.asp, (4) the iData parameter to detail.asp or result.asp, the (5) POL_ID, (6) POL_PARENT, (7) POL_CATEGORY, (8) CHA_NAME, or (9) CHA_ID parameters to inc_vote.asp, or the (10) tfm_order or (11) tfm_orderby parameters to toppages.asp, a different set of vulnerabilities than CVE-2005-1236.

    Published: 22 Apr 2005
    4.6
    Medium

    CVE-2005-0758

    Last Modified: 16 Apr 2026

    zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.

    Published: 22 Apr 2005
    7.5
    High

    CVE-2005-1195

    Last Modified: 16 Apr 2026

    Multiple heap-based buffer overflows in the code used to handle (1) MMS over TCP (MMST) streams or (2) RealMedia RTSP streams in xine-lib before 1.0, and other products that use xine-lib such as MPlayer 1.0pre6 and earlier, allow remote malicious servers to execute arbitrary code.

    Published: 21 Apr 2005
    7.5
    High

    CVE-2005-1196

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in kb.php in the Knowledge Base module for phpBB allows remote attackers to obtain sensitive information and execute SQL commands via the cat parameter.

    Published: 21 Apr 2005
    6.8
    Medium

    CVE-2005-1202

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in eGroupware before 1.0.0.007 allow remote attackers to inject arbitrary web script or HTML via the (1) ab_id, (2) page, (3) type, or (4) lang parameter to index.php or (5) category_id parameter.

    Published: 21 Apr 2005
    5
    Medium

    CVE-2005-1204

    Last Modified: 16 Apr 2026

    Desktop Rover 3.0, and possibly earlier versions, allows remote attackers to cause a denial of service (application crash) via a crafted packet to TCP port 61427, which causes an invalid memory access.

    Published: 21 Apr 2005
    7.5
    High

    CVE-2005-1203

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in eGroupware before 1.0.0.007 allow remote attackers to execute arbitrary SQL commands via the (1) filter or (2) cats_app parameter.

    Published: 21 Apr 2005
    7.5
    High

    CVE-2005-1197

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the SYS.DBMS_CDC_IPUBLISH.CREATE_SCN_CHANGE_SET procedure in Oracle Database Server 10g allows remote attackers to execute arbitrary SQL commands via the CHANGE_SET_NAME parameter.

    Published: 21 Apr 2005
    5
    Medium

    CVE-2005-1198

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in apexec.pl for Anaconda Foundation Directory allows remote attackers to read arbitrary files via hex-encoded null characters (%00) in the middle of ".." sequences in the template parameter.

    Published: 21 Apr 2005
    6.4
    Medium

    CVE-2005-1201

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in AZ Bulletin board (AZbb) before 1.0.08 allow (1) remote authenticated users with administrative privileges to delete arbitrary files via a .. (dot dot) in the URL to admin_avatar.php or admin_attachment.php or (2) remote attackers to enumerate files via a .. (dot dot) in the attachment parameter to attachment.php, which displays a different message when a file exists or does not exist.

    Published: 21 Apr 2005
    7.5
    High

    CVE-2005-1200

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in main_index.php in AZ Bulletin Board (AZbb) 1.0.07a through 1.0.07c allows remote attackers to execute arbitrary PHP code by modifying the (1) dir_src or (2) abs_layer parameter to reference a URL on a remote web server that contains the code.

    Published: 21 Apr 2005
    5.1
    Medium

    CVE-2005-0035

    Last Modified: 16 Apr 2026

    The Acrobat web control in Adobe Acrobat and Acrobat Reader 7.0 and earlier, when used with Internet Explorer, allows remote attackers to determine the existence of arbitrary files via the LoadFile ActiveX method.

    Published: 21 Apr 2005
    7.5
    High

    CVE-2005-1199

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in printthread.php in UBB.Threads allows remote attackers to execute arbitrary SQL commands via the main parameter.

    Published: 21 Apr 2005
    5.1
    Medium

    CVE-2005-1227

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in PHProjekt 4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the chatroom text submission form.

    Published: 20 Apr 2005
    4.3
    Medium

    CVE-2005-1233

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in PHP Labs proFile allows remote attackers to inject arbitrary web script or HTML via the (1) dir or (2) file parameters.

    Published: 20 Apr 2005
    7.5
    High

    CVE-2005-1240

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the third party tool from Castlehill, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request.

    Published: 20 Apr 2005
    7.5
    High

    CVE-2005-1241

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the third party tool from Powertech, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request.

    Published: 20 Apr 2005
    7.5
    High

    CVE-2005-1244

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the third party tool from NetIQ, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request. NOTE: the vendor has disputed this issue, saying that "neither NetIQ Security Manager nor our iSeries Security Solutions are vulnerable.

    Published: 20 Apr 2005
    4.6
    Medium

    CVE-2005-1229

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in cpio 2.6 and earlier allows remote attackers to write to arbitrary directories via a .. (dot dot) in a cpio file.

    Published: 20 Apr 2005
    5
    Medium

    CVE-2005-1180

    Last Modified: 16 Apr 2026

    HTTP Response Splitting vulnerability in the Surveys module in PHP-Nuke 7.6 allows remote attackers to spoof web content and poison web caches via hex-encoded CRLF ("%0d%0a") sequences in the forwarder parameter.

    Published: 19 Apr 2005
    5
    Medium

    CVE-2005-1182

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Incoming Remote Command (iSeries Access for Windows Remote Command service) in IBM OS/400 R510, R520, and R530 allows attackers to cause a denial of service (IRC shutdown) via certain inputs.

    Published: 19 Apr 2005
    4.3
    Medium

    CVE-2005-1183

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in mvnForum 1.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the Search parameter.

    Published: 19 Apr 2005
    5.1
    Medium

    CVE-2005-1187

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in WinHex 12.05 SR-14, and possibly other versions, may allow attackers to execute arbitrary code via a long file name argument. NOTE: since this overflow is in the command line of an unprivileged program, it is highly likely that this is not a vulnerability.

    Published: 19 Apr 2005
    4.3
    Medium

    CVE-2005-1188

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in comersus_searchItem.asp in Comersus 3.90 to 4.51 allows remote attackers to inject arbitrary web script or HTML via the curPage parameter.

    Published: 19 Apr 2005
    4.3
    Medium

    CVE-2005-1189

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in WebcamXP PRO v2.16.468 and earlier allows remote attackers to inject arbitrary web script or HTML via the chat name, as demonstrated by using an IFRAME to redirect users to other sites.

    Published: 19 Apr 2005
    5
    Medium

    CVE-2005-1190

    Last Modified: 16 Apr 2026

    WebcamXP PRO v2.16.468 and earlier allows remote attackers to cause a denial of service via a long chat name, which takes up too much display space and prevents the chat frame from being properly rendered.

    Published: 19 Apr 2005
    10
    Critical

    CVE-2005-1177

    Last Modified: 16 Apr 2026

    Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, with unknown impact.

    Published: 19 Apr 2005
    7.5
    High

    CVE-2005-1178

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Oracle Forms 10g allows remote attackers to execute arbitrary SQL commands via the Query/Where feature.

    Published: 19 Apr 2005
    5
    Medium

    CVE-2005-1179

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Xerox MicroServer Web Server for various WorkCentre products including M35/M45/M55 2.028.11.000 through 2.97.20.032 and 4.84.16.000 through 4.97.20.032, Pro 35/45/55 3.028.11.000 through 3.97.20.032, Pro 65/75/90 1.001.00.060 through 1.001.02.084, and others, related to SNMP authentication, allows remote attackers to modify system configuration, a different vulnerability than CVE-2005-0703.

    Published: 19 Apr 2005
    4.6
    Medium

    CVE-2005-1185

    Last Modified: 16 Apr 2026

    Unquoted Windows search path vulnerability in Musicmatch Jukebox 10.00.2047 and earlier allows local users to gain privileges via a malicious C:\program.exe file, which is run by MMFWLaunch.exe when it attempts to execute launch.exe.

    Published: 19 Apr 2005
    6.8
    Medium

    CVE-2005-1186

    Last Modified: 16 Apr 2026

    Musicmatch Jukebox 10.00.2047 and earlier adds the musicmatch.com domain to the Trusted Sites zone in Internet Explorer, which allows systems in the domain to conduct unauthorized activities, as demonstrated using cross-site scripting (XSS) attacks.

    Published: 19 Apr 2005
    7.5
    High

    CVE-2005-1181

    Last Modified: 16 Apr 2026

    NOTE: this issue has been disputed by the vendor. PHP remote code injection vulnerability in loader.php for Ariadne CMS 2.4 allows remote attackers to execute arbitrary PHP code by modifying the ariadne parameter to reference a URL on a remote web server that contains the code. NOTE: the vendor has disputed this issue, saying that loader.php first requires the "ariadne.inc" file, which defines the $ariadne variable, and thus it cannot be modified by an attacker. In addition, CVE personnel have partially verified the dispute via source code inspection of Ariadne 2.4 as available on July 5, 2005

    Published: 19 Apr 2005
    5
    Medium

    CVE-2005-1191

    Last Modified: 16 Apr 2026

    The Web View DLL (webvw.dll), as used in Windows Explorer on Windows 2000 systems, does not properly filter an apostrophe ("'") in the author name in a document, which allows attackers to execute arbitrary script via extra attributes when Web View constructs a mailto: link for the preview pane when the user selects the file.

    Published: 19 Apr 2005
    4.3
    Medium

    CVE-2004-1341

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in info2www before 1.2.2.9 allows remote attackers to inject arbitrary web script or HTML via the arguments to info2www.

    Published: 19 Apr 2005
    5
    Medium

    CVE-2005-0391

    Last Modified: 16 Apr 2026

    geneweb 4.10 and earlier does not properly check file permissions and content during conversion, which allows attackers to modify arbitrary files.

    Published: 19 Apr 2005
    1.2
    Low

    CVE-2005-1176

    Last Modified: 16 Apr 2026

    Race condition in JFS2 on AIX 5.2 and 5.3, when deleting a file while I/O is still occurring for that file, may write data to a different file, which could leak sensitive information.

    Published: 19 Apr 2005
    5
    Medium

    CVE-2005-1184

    Last Modified: 16 Apr 2026

    The TCP/IP stack in multiple operating systems allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the correct sequence number but the wrong Acknowledgement number, which generates a large number of "keep alive" packets. NOTE: some followups indicate that this issue could not be replicated.

    Published: 19 Apr 2005
    5.1
    Medium

    CVE-2005-0755

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in RealPlayer 10 and earlier, Helix Player before 10.0.4, and RealOne Player v1 and v2 allows remote attackers to execute arbitrary code via a long hostname in a RAM file.

    Published: 19 Apr 2005
    7.2
    High

    CVE-2005-1107

    Last Modified: 16 Apr 2026

    McAfee Internet Security Suite 2005 uses insecure default ACLs for installed files, which allows local users to gain privileges or disable protection by modifying certain files.

    Published: 18 Apr 2005
    5.8
    Medium

    CVE-2005-1162

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in OneWorldStore allow remote attackers to inject arbitrary web script or HTML via the (1) sEmail parameter to owContactUs.asp, (2) bSub parameter to owListProduct.asp, or the (3) Name, (4) Email, or (5) Comment fields in owProductDetail.asp.

    Published: 18 Apr 2005
    6.4
    Medium

    CVE-2005-1163

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Yager 5.24 and earlier allow remote attackers to execute arbitrary code via (1) a crafted nickname or (2) a packet with a large amount of data.

    Published: 18 Apr 2005
    5
    Medium

    CVE-2005-1165

    Last Modified: 16 Apr 2026

    Yager 5.24 and earlier allows remote attackers to cause a denial of service (application crash) via certain malformed data.

    Published: 18 Apr 2005
    5
    Medium

    CVE-2005-1164

    Last Modified: 16 Apr 2026

    Yager 5.24 and earlier allows remote attackers to cause a denial of service (application hang) via a packet with a game header that provides less data than indicated by the length.

    Published: 18 Apr 2005
    7.5
    High

    CVE-2005-1170

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in mod.php in the datenbank module for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 18 Apr 2005
    4.3
    Medium

    CVE-2005-1171

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in mod.php in the datenbank module for phpBB allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 18 Apr 2005
    4.3
    Medium

    CVE-2005-1172

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in init.inc.php in Coppermine Photo Gallery 1.3.x allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For parameter.

    Published: 18 Apr 2005
    7.5
    High

    CVE-2005-1173

    Last Modified: 16 Apr 2026

    Buffer overflow in PMSoftware Simple Web Server 1.0 allows remote attackers to execute arbitrary code via a long GET request.

    Published: 18 Apr 2005
    7.5
    High

    CVE-2005-1161

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in OneWorldStore allow remote attackers to execute arbitrary SQL commands via the idProduct parameter to (1) owAddItem.asp or (2) owProductDetail.asp, (3) idCategory parameter to owListProduct.asp, or (4) bSpecials parameter to owListProduct.asp.

    Published: 18 Apr 2005