CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2005-1139

    Last Modified: 16 Apr 2026

    Opera 8 Beta 3, when using first-generation vetted digital certificates, displays the Organizational information of an SSL certificate, which is easily spoofed and can facilitate phishing attacks.

    Published: 14 Apr 2005
    4.3
    Medium

    CVE-2005-1118

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in IISWebAgentIF.dll in the RSA Authentication Agent for Web 5.2 allows remote attackers to inject arbitrary web script or HTML via the postdata parameter.

    Published: 14 Apr 2005
    5
    Medium

    CVE-2005-1136

    Last Modified: 16 Apr 2026

    Simple PHP Blog (sphpBlog) 0.4.0 stores the (1) password.txt and (2) config.txt files under the web document root, which allows remote attackers to obtain sensitive information and crack passwords via a direct request to these files.

    Published: 14 Apr 2005
    7.2
    High

    CVE-2005-1088

    Last Modified: 16 Apr 2026

    Unknown vulnerability in DameWare NT Utilities 4.8 and earlier, and Mini Remote Control 4.8 and earlier, allows local users to gain additional rights.

    Published: 13 Apr 2005
    6.4
    Medium

    CVE-2005-1090

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the readFile and writeFile API for Maxthon 1.2.0 and 1.2.1 allows remote attackers to read or write arbitrary files.

    Published: 13 Apr 2005
    7.5
    High

    CVE-2005-1091

    Last Modified: 16 Apr 2026

    Maxthon 1.2.0 and 1.2.1 allows remote attackers to bypass the security ID and use restricted plugin API functions via script that includes the max.src file into the source page.

    Published: 13 Apr 2005
    7.2
    High

    CVE-2005-1092

    Last Modified: 16 Apr 2026

    Lightspeed DeluxeFTP 6.01 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges.

    Published: 13 Apr 2005
    4.3
    Medium

    CVE-2005-1095

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in main.asp for Ocean12 Membership Manager Pro 1.x allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 13 Apr 2005
    4.6
    Medium

    CVE-2005-1097

    Last Modified: 16 Apr 2026

    Rebrand P2P Share Spy 2.2 stores the user password in plaintext in the txtPassword value in the registry, which allows local users to gain privileges.

    Published: 13 Apr 2005
    2.1
    Low

    CVE-2005-1098

    Last Modified: 16 Apr 2026

    GetDataBack for NTFS 2.31 stores the username and license key in plaintext in the Name value in the License registry key, which may allow local users to obtain sensitive information.

    Published: 13 Apr 2005
    6.8
    Medium

    CVE-2005-1102

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in template-functions-post.php in WordPress 1.5 and earlier allow remote attackers to execute arbitrary commands via the (1) content or (2) title of the post.

    Published: 13 Apr 2005
    4.3
    Medium

    CVE-2005-1104

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Centra 7 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) first name, or (3) last name fields.

    Published: 13 Apr 2005
    5
    Medium

    CVE-2005-1105

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the MimeBodyPart.getFileName method in JavaMail 1.3.2 allows remote attackers to write arbitrary files via a .. (dot dot) in the filename in the Content-Disposition header.

    Published: 13 Apr 2005
    5
    Medium

    CVE-2005-1106

    Last Modified: 16 Apr 2026

    PictureViewer in QuickTime for Windows 6.5.2 allows remote attackers to cause a denial of service (application crash) via a GIF image with the maximum depth start value, possibly triggering an integer overflow.

    Published: 13 Apr 2005
    7.5
    High

    CVE-2005-1149

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in admin/login.asp in aspclick.it ACNews 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.

    Published: 13 Apr 2005
    2.6
    Low

    CVE-2005-1301

    Last Modified: 16 Apr 2026

    nProtect:Netizen 2005.3.17.1 does not properly verify that the update module is downloaded from an authorized site, which allows remote malicious web sites to write arbitrary files.

    Published: 13 Apr 2005
    6.4
    Medium

    CVE-2005-1086

    Last Modified: 16 Apr 2026

    Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via an HTTP request with a long User-Agent header.

    Published: 13 Apr 2005
    7.5
    High

    CVE-2005-1101

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Lotus Domino Server 6.0.5 and 6.5.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via large amounts of data in certain (1) time or (2) date fields.

    Published: 13 Apr 2005
    7.2
    High

    CVE-2005-0060

    Last Modified: 16 Apr 2026

    Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.

    Published: 13 Apr 2005
    5.1
    Medium

    CVE-2005-0553

    Last Modified: 16 Apr 2026

    Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".

    Published: 13 Apr 2005
    7.5
    High

    CVE-2005-1093

    Last Modified: 16 Apr 2026

    Buffer overflow in the PopUp Plus 2.0.3.8 plugin for Miranda IM, with "Use SmileyAdd Setting" enabled, allows remote attackers to execute arbitrary code.

    Published: 13 Apr 2005
    7.5
    High

    CVE-2005-1100

    Last Modified: 16 Apr 2026

    Format string vulnerability in the ErrorLog function in cnf.c in Greylisting daemon (GLD) 1.3 and 1.4 allows remote attackers to execute arbitrary code via format string specifiers in data that is passed directly to syslog.

    Published: 13 Apr 2005
    10
    Critical

    CVE-2005-0059

    Last Modified: 16 Apr 2026

    Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.

    Published: 13 Apr 2005
    7.5
    High

    CVE-2005-0063

    Last Modified: 16 Apr 2026

    The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.

    Published: 13 Apr 2005
    7.5
    High

    CVE-2005-0554

    Last Modified: 16 Apr 2026

    Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."

    Published: 13 Apr 2005
    7.2
    High

    CVE-2005-0061

    Last Modified: 16 Apr 2026

    The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.

    Published: 13 Apr 2005
    5
    Medium

    CVE-2005-0404

    Last Modified: 16 Apr 2026

    KMail 1.7.1 in KDE 3.3.2 allows remote attackers to spoof email information, such as whether the email has been digitally signed or encrypted, via HTML formatted email.

    Published: 13 Apr 2005
    2.1
    Low

    CVE-2005-0550

    Last Modified: 16 Apr 2026

    Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka "Object Management Vulnerability".

    Published: 13 Apr 2005
    7.5
    High

    CVE-2005-0560

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server 2000 and 2003 allows remote attackers to execute arbitrary code via a crafted X-LINK2STATE extended verb request to the SMTP port.

    Published: 13 Apr 2005
    7.5
    High

    CVE-2005-0048

    Last Modified: 16 Apr 2026

    Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the "IP Validation Vulnerability."

    Published: 13 Apr 2005
    10
    Critical

    CVE-2005-0551

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value.

    Published: 13 Apr 2005
    5.1
    Medium

    CVE-2005-0558

    Last Modified: 16 Apr 2026

    Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.

    Published: 13 Apr 2005
    7.5
    High

    CVE-2005-1134

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in exit.php for Serendipity 0.8 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) url_id or (2) entry_id parameters.

    Published: 13 Apr 2005
    4.7
    Medium

    CVE-2005-1111

    Last Modified: 16 Apr 2026

    Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.

    Published: 13 Apr 2005
    7.5
    High

    CVE-2005-1048

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in modules.php in PostNuke 0.760 RC3 allows remote attackers to execute arbitrary SQL statements via the sid parameter. NOTE: the vendor reports that they could not reproduce the issues for 760 RC3, or for .750.

    Published: 12 Apr 2005
    Unknown

    CVE-2005-1044

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-0941. Reason: This candidate is a duplicate of CVE-2005-0941. Notes: All CVE users should reference CVE-2005-0941 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 12 Apr 2005
    4.3
    Medium

    CVE-2005-1053

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in orderwiz.php in ModernBill 4.3.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) c_code or (2) aid parameters.

    Published: 12 Apr 2005
    7.5
    High

    CVE-2005-1054

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in news.php in ModernBill 4.3.0 and earlier allows remote attackers to execute arbitrary PHP code by modifying the DIR parameter to reference a URL on a remote web server that contains the code.

    Published: 12 Apr 2005
    2.1
    Low

    CVE-2005-1065

    Last Modified: 16 Apr 2026

    tetex in Novell Linux Desktop 9 allows local users to determine the existence of arbitrary files via a symlink attack in the /var/cache/fonts directory.

    Published: 12 Apr 2005
    10
    Critical

    CVE-2005-1069

    Last Modified: 16 Apr 2026

    Unknown vulnerability in sCssBoard 1.11 and earlier has unknown impact, related to "an exploit on the Profile page."

    Published: 12 Apr 2005
    7.5
    High

    CVE-2005-1071

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in banner.inc.php in JPortal Web Portal 2.3.1 allows remote attackers to execute arbitrary SQL commands via the haslo parameter.

    Published: 12 Apr 2005
    5
    Medium

    CVE-2005-1073

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php for RadScripts RadBids Gold 2 allows remote attackers to read arbitrary files via the read parameter.

    Published: 12 Apr 2005
    7.5
    High

    CVE-2005-1074

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php for RadScripts RadBids Gold 2 allows remote attackers to execute arbitrary SQL commands via the mode parameter.

    Published: 12 Apr 2005
    7.5
    High

    CVE-2005-1079

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php for zOOm Media Gallery 2.1.2 allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Published: 12 Apr 2005
    4.3
    Medium

    CVE-2005-1081

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in view.php in AzDGDatingPlatinum 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 12 Apr 2005
    5
    Medium

    CVE-2005-1083

    Last Modified: 16 Apr 2026

    index.php in aeDating 3.2 allows remote attackers to include arbitrary files via the skin parameter.

    Published: 12 Apr 2005
    7.5
    High

    CVE-2005-1084

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in sdating.php in aeDating 3.2 allows remote attackers to execute arbitrary SQL commands files via the event parameter.

    Published: 12 Apr 2005
    10
    Critical

    CVE-2005-1099

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the HandleChild function in server.c in Greylisting daemon (GLD) 1.3 and 1.4, when GLD is listening on a network interface, allow remote attackers to execute arbitrary code.

    Published: 12 Apr 2005
    4.3
    Medium

    CVE-2005-1130

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Pinnacle Cart allows remote attackers to inject arbitrary web script or HTML via the pg parameter.

    Published: 12 Apr 2005
    5
    Medium

    CVE-2005-1147

    Last Modified: 16 Apr 2026

    calendar.pl in CalendarScript 3.20 allows remote attackers to obtain sensitive information via invalid (1) calendar or (2) template parameters, which leaks the full pathname and debug information.

    Published: 12 Apr 2005