CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2005-1166

    Last Modified: 16 Apr 2026

    The DNTUS26 process in Dameware NT Utilities and the DWRCS process in MiniRemote Control 4.9 and earlier stores the username and password in cleartext in memory, which could allow attackers to obtain sensitive information.

    Published: 18 Apr 2005
    7.5
    High

    CVE-2005-1169

    Last Modified: 16 Apr 2026

    Mafia Blog .4 BETA does not properly protect the admin directory, which allows remote attackers to execute arbitrary PHP code by using writeinfo.php to inject the code into info.php.

    Published: 18 Apr 2005
    5
    Medium

    CVE-2005-0976

    Last Modified: 16 Apr 2026

    AppleWebKit (WebCore and WebKit), as used in multiple products such as Safari 1.2 and OmniGroup OmniWeb 5.1, allows remote attackers to read arbitrary files via the XMLHttpRequest Javascript component, as demonstrated using automatically mounted disk images and file:// URLs.

    Published: 18 Apr 2005
    5
    Medium

    CVE-2005-1168

    Last Modified: 16 Apr 2026

    DiagCollectionControl.dll in Musicmatch 10.00.2047 and earlier allows remote attackers to overwrite arbitrary files via the bstrSavePath argument.

    Published: 18 Apr 2005
    Unknown

    CVE-2005-0093

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 18 Apr 2005
    2.1
    Low

    CVE-2005-1167

    Last Modified: 16 Apr 2026

    Musicmatch 10.00.2047 and earlier store log files in the Program Files directory instead of the user profile, which may allow local users to obtain sensitive information.

    Published: 18 Apr 2005
    7.5
    High

    CVE-2005-0753

    Last Modified: 16 Apr 2026

    Buffer overflow in CVS before 1.11.20 allows remote attackers to execute arbitrary code.

    Published: 18 Apr 2005
    5
    Medium

    CVE-2005-1228

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot dot) in the original filename within a compressed file.

    Published: 18 Apr 2005
    5
    Medium

    CVE-2005-1108

    Last Modified: 16 Apr 2026

    The ij_untrusted_url function in JunkBuster 2.0.2-r2, with single-threaded mode enabled, allows remote attackers to overwrite the referrer field via a crafted HTTP request.

    Published: 16 Apr 2005
    5
    Medium

    CVE-2005-1112

    Last Modified: 16 Apr 2026

    IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via an HTTP request with an invalid Host header, which causes the page to be processed by the web server instead of the JSP engine.

    Published: 16 Apr 2005
    4.3
    Medium

    CVE-2005-1113

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PhpBB Plus 1.52 and earlier allow remote attackers to inject arbitrary web script or HTML via the bsid parameter to (1) groupcp.php, (2) index.php, (3) portal.php, (4) viewforum.php, or (5) viewtopic.php, (6) the c parameter to index.php, or (7) the article parameter to portal.php.

    Published: 16 Apr 2005
    7.5
    High

    CVE-2005-1114

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in album_search.php in Photo Album 2.0.53 for phpBB allow remote attackers to execute arbitrary SQL commands via the (1) mode or (2) search parameters.

    Published: 16 Apr 2005
    4.3
    Medium

    CVE-2005-1115

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Photo Album 2.0.53 module for phpBB allow remote attackers to inject arbitrary web script or HTML via the bsid parameter to (1) album_cat.php or (2) album_comment.php.

    Published: 16 Apr 2005
    4.3
    Medium

    CVE-2005-1116

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Calendar module for phpBB allow remote attackers to inject arbitrary web script or HTML via the start parameter to calendar_scheduler.php.

    Published: 16 Apr 2005
    2.1
    Low

    CVE-2005-1119

    Last Modified: 16 Apr 2026

    Sudo VISudo 1.6.8 and earlier allows local users to corrupt arbitrary files via a symlink attack on temporary files.

    Published: 16 Apr 2005
    4.3
    Medium

    CVE-2005-1120

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in IlohaMail 0.8.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the e-mail (1) body, (2) filename, or (3) MIME type.

    Published: 16 Apr 2005
    5
    Medium

    CVE-2005-1121

    Last Modified: 16 Apr 2026

    Format string vulnerability in the my_xlog function in lib.c for Oops! Proxy Server 1.5.23 and earlier, as called by the auth functions in the passwd_mysql and passwd_pgsql modules, may allow attackers to execute arbitrary code via a URL.

    Published: 16 Apr 2005
    5
    Medium

    CVE-2005-1123

    Last Modified: 16 Apr 2026

    Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service (memory corruption) via a request for a zero byte file.

    Published: 16 Apr 2005
    4.6
    Medium

    CVE-2005-1124

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the libgss Generic Security Services Library in Solaris 7, 8, and 9 allows local users to gain privileges by loading their own GSS-API.

    Published: 16 Apr 2005
    7.5
    High

    CVE-2005-1128

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in VHCS 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via certain inputs from HTTP POST queries.

    Published: 16 Apr 2005
    2.1
    Low

    CVE-2005-1129

    Last Modified: 16 Apr 2026

    eGroupWare 1.0.6 and earlier, when an e-mail is composed with an attachment but not sent, will send that attachment in the next e-mail, which may cause sensitive information to be sent to the wrong recipient.

    Published: 16 Apr 2005
    5
    Medium

    CVE-2005-1132

    Last Modified: 16 Apr 2026

    LG U8120 mobile phone allows remote attackers to cause a denial of service (device crash) via a malformed MIDI file.

    Published: 16 Apr 2005
    5
    Medium

    CVE-2005-1133

    Last Modified: 16 Apr 2026

    The POP3 server in IBM iSeries AS/400 returns different error messages when the user exists or not, which allows remote attackers to determine valid user IDs on the server.

    Published: 16 Apr 2005
    5
    Medium

    CVE-2005-1138

    Last Modified: 16 Apr 2026

    Unknown vulnerability in WebMail in Kerio MailServer before 6.0.9 allows remote attackers to cause a denial of service (CPU consumption) via certain e-mail messages.

    Published: 16 Apr 2005
    5
    Medium

    CVE-2005-1150

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Sun Java System Web Server 6.0 SP7 and earlier, when running on Windows systems, allows attackers to cause a denial of service (hang).

    Published: 16 Apr 2005
    7.5
    High

    CVE-2005-1109

    Last Modified: 16 Apr 2026

    The filtering of URLs in JunkBuster before 2.0.2-r3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via heap corruption.

    Published: 16 Apr 2005
    7.5
    High

    CVE-2005-1110

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the RespondeHTTPPendiente function in the HTTP server for SUMUS 0.2.2 allows remote attackers to execute arbitrary code via a large packet sent to TCP port 81.

    Published: 16 Apr 2005
    10
    Critical

    CVE-2005-1131

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Veritas i3 Focalpoint Server 7.1 and earlier has unknown attack vectors and unknown but "critical" impact.

    Published: 16 Apr 2005
    5
    Medium

    CVE-2005-1137

    Last Modified: 16 Apr 2026

    Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to obtain sensitive information via a direct request to sb_functions.php, which leaks the full pathname in a PHP error message.

    Published: 16 Apr 2005
    4.3
    Medium

    CVE-2005-1135

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php for Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Published: 16 Apr 2005
    5
    Medium

    CVE-2005-1148

    Last Modified: 16 Apr 2026

    calendar.pl in CalendarScript 3.21 allows remote attackers to obtain sensitive information via invalid (1) year or (2) month parameters, which leaks the full pathname and debug information.

    Published: 16 Apr 2005
    7.5
    High

    CVE-2005-1117

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in All4WWW-Homepagecreator 1.0a allows remote attackers to execute arbitrary PHP code by modifying the site parameter to reference a URL on a remote web server that contains the code.

    Published: 16 Apr 2005
    5.1
    Medium

    CVE-2005-1125

    Last Modified: 16 Apr 2026

    Race condition in libsafe 2.0.16 and earlier, when running in multi-threaded applications, allows attackers to bypass libsafe protection and exploit other vulnerabilities before the _libsafe_die function call is completed.

    Published: 16 Apr 2005
    5
    Medium

    CVE-2005-1127

    Last Modified: 16 Apr 2026

    Format string vulnerability in the log function in Net::Server 0.87 and earlier, as used in Postfix Greylisting Policy Server (Postgrey) 1.18 and earlier, and possibly other products, allows remote attackers to cause a denial of service (crash) via format string specifiers that are not properly handled before being sent to syslog, as demonstrated using sender addresses to Postgrey.

    Published: 16 Apr 2005
    4.3
    Medium

    CVE-2005-1140

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in myBloggie 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the comments.

    Published: 15 Apr 2005
    7.5
    High

    CVE-2005-1142

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the readpgm function in pnm.c for GOCR 0.40, when it is not using netpbm, allows remote attackers to execute arbitrary code via a P3 format PNM file with more data than implied by its width and height values.

    Published: 15 Apr 2005
    7.5
    High

    CVE-2005-1308

    Last Modified: 16 Apr 2026

    SqWebMail allows remote attackers to inject arbitrary web script or HTML via CRLF sequences in the redirect parameter followed by the desired script or HTML.

    Published: 15 Apr 2005
    2.1
    Low

    CVE-2005-1126

    Last Modified: 16 Apr 2026

    The SIOCGIFCONF ioctl (ifconf function) in FreeBSD 4.x through 4.11 and 5.x through 5.4 does not properly clear a buffer before using it, which allows local users to obtain portions of sensitive kernel memory.

    Published: 15 Apr 2005
    Unknown

    CVE-2002-1370

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1367. Reason: This CAN was originally assigned for the theft of root certificates in CUPS, but it was later deemed to be a legitimate result of exploiting a different vulnerability, CVE-2002-1367, so it is not a distinct vulnerability. Notes: All CVE users should reference CVE-2002-1367 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 15 Apr 2005
    9.8
    Critical

    CVE-2005-1141

    Last Modified: 16 Apr 2026

    Integer overflow in the readpgm function in pnm.c for GOCR 0.40, when using the netpbm library, allows remote attackers to execute arbitrary code via a PNM file with large width and height values, which leads to a heap-based buffer overflow.

    Published: 15 Apr 2005
    7.5
    High

    CVE-2005-1155

    Last Modified: 16 Apr 2026

    The favicon functionality in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary code via a <LINK rel="icon"> tag with a javascript: URL in the href attribute, aka "Firelinking."

    Published: 15 Apr 2005
    7.5
    High

    CVE-2005-1156

    Last Modified: 16 Apr 2026

    Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to execute arbitrary script and code via a new search plugin using sidebar.addSearchEngine, aka "Firesearching 1."

    Published: 15 Apr 2005
    5
    Medium

    CVE-2005-1158

    Last Modified: 16 Apr 2026

    Multiple "missing security checks" in Firefox before 1.0.3 allow remote attackers to inject arbitrary Javascript into privileged pages using the _search target of the Firefox sidebar.

    Published: 15 Apr 2005
    7.5
    High

    CVE-2005-1153

    Last Modified: 16 Apr 2026

    Firefox before 1.0.3 and Mozilla Suite before 1.7.7, when blocking a popup, allows remote attackers to execute arbitrary code via a javascript: URL that is executed when the user selects the "Show javascript" option.

    Published: 15 Apr 2005
    7.5
    High

    CVE-2005-1154

    Last Modified: 16 Apr 2026

    Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary script in other domains via a setter function for a variable in the target domain, which is executed when the user visits that domain, aka "Cross-site scripting through global scope pollution."

    Published: 15 Apr 2005
    5.1
    Medium

    CVE-2005-1160

    Last Modified: 16 Apr 2026

    The privileged "chrome" UI code in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to gain privileges by overriding certain properties or methods of DOM nodes, as demonstrated using multiple attacks involving the eval function or the Script object.

    Published: 15 Apr 2005
    7.5
    High

    CVE-2005-1157

    Last Modified: 16 Apr 2026

    Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to replace existing search plugins with malicious ones using sidebar.addSearchEngine and the same filename as the target engine, which may not be displayed in the GUI, which could then be used to execute malicious script, aka "Firesearching 2."

    Published: 15 Apr 2005
    7.5
    High

    CVE-2005-0752

    Last Modified: 16 Apr 2026

    The Plugin Finder Service (PFS) in Firefox before 1.0.3 allows remote attackers to execute arbitrary code via a javascript: URL in the PLUGINSPAGE attribute of an EMBED tag.

    Published: 15 Apr 2005
    7.5
    High

    CVE-2005-1159

    Last Modified: 16 Apr 2026

    The native implementations of InstallTrigger and other functions in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 do not properly verify the types of objects being accessed, which causes the Javascript interpreter to continue execution at the wrong memory address, which may allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code by passing objects of the wrong type.

    Published: 15 Apr 2005
    7.5
    High

    CVE-2005-1122

    Last Modified: 16 Apr 2026

    Format string vulnerability in cgi.c for Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP GET request containing double-encoded format string specifiers (aka "double expansion error").

    Published: 14 Apr 2005