CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2005-1144

    Last Modified: 16 Apr 2026

    popup.php in EasyPHPCalendar before 6.2.8 allows remote attackers to obtain sensitive information via an invalid ev parameter, which reveals the full pathname of the web server in a PHP error message.

    Published: 12 Apr 2005
    2.6
    Low

    CVE-2005-1049

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting vulnerabilities in PostNuke 0.760-RC3 allow remote attackers to inject arbitrary web script or HTML via the (1) module parameter to admin.php or (2) op parameter to user.php. NOTE: the vendor reports that certain issues could not be reproduced for 760 RC3, or for .750. However, the op/user.php issue exists when the pnAntiCracker setting is disabled.

    Published: 12 Apr 2005
    6.5
    Medium

    CVE-2005-1051

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in profile.php in PunBB 1.2.4 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a change_email action.

    Published: 12 Apr 2005
    5
    Medium

    CVE-2005-1056

    Last Modified: 16 Apr 2026

    Unknown vulnerability in HP OpenView Network Node Manager (NMM) 6.2 through 6.4, and 7.01 through 7.50, allows remote attackers to cause a denial of service.

    Published: 12 Apr 2005
    7.5
    High

    CVE-2005-1057

    Last Modified: 16 Apr 2026

    Cisco IOS 12.2T, 12.3 and 12.3T, when using Easy VPN Server XAUTH version 6 authentication, allows remote attackers to bypass authentication via a "malformed packet."

    Published: 12 Apr 2005
    5
    Medium

    CVE-2005-1060

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the TCP/IP functionality (TCPIP.NLM) in Novell Netware 6.x allows remote attackers to cause a denial of service (ABEND by Page Fault Processor Exception) via certain packets.

    Published: 12 Apr 2005
    4.3
    Medium

    CVE-2005-1068

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in sCssBoard 1.11 and earlier allows remote attackers to execute arbitrary Javascript via [url] tags.

    Published: 12 Apr 2005
    4.3
    Medium

    CVE-2005-1075

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in RadScripts RadBids Gold 2 allow remote attackers to inject arbitrary web script or HTML via (1) the farea parameter to faq.php or the (2) cat, (3) order, or (4) area parameters to index.php.

    Published: 12 Apr 2005
    4.3
    Medium

    CVE-2005-1076

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the discussion board functionality for WebCT Campus Edition 4.1 allows remote attackers to inject arbitrary web script or HTML via the message field.

    Published: 12 Apr 2005
    7.5
    High

    CVE-2005-1078

    Last Modified: 16 Apr 2026

    XAMPP 1.4.x has multiple default or null passwords, which allows attackers to gain privileges.

    Published: 12 Apr 2005
    4.6
    Medium

    CVE-2005-1103

    Last Modified: 16 Apr 2026

    Sygate Security Agent (SSA) in Sygate Secure Enterprise 3.5 through 4.1 does not prevent the security policy from being updated by unprivileged users, which allows local users to modify the policy by exporting the policy file, changing it, and importing it back into SSA.

    Published: 12 Apr 2005
    4.3
    Medium

    CVE-2005-1143

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in EasyPHPCalendar before 6.2.8 allows remote attackers to inject arbitrary web script or HTML via the yr parameter.

    Published: 12 Apr 2005
    4.3
    Medium

    CVE-2005-1145

    Last Modified: 16 Apr 2026

    NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in calendar.pl in CalendarScript 3.20 allows remote attackers to inject arbitrary web script or HTML via the template parameter, a different vulnerability than CVE-2005-1146

    Published: 12 Apr 2005
    4.3
    Medium

    CVE-2005-1146

    Last Modified: 16 Apr 2026

    NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in the login command in calendar.pl in CalendarScript 3.21 allows remote attackers to inject arbitrary web script or HTML via the username parameter, a different vulnerability than CVE-2005-1145

    Published: 12 Apr 2005
    7.5
    High

    CVE-2005-1018

    Last Modified: 16 Apr 2026

    Buffer overflow in the UniversalAgent for Computer Associates (CA) BrightStor ARCserve Backup allows remote authenticated users to cause a denial of service or execute arbitrary code via an agent request to TCP port 6050 with a large argument before the option field.

    Published: 12 Apr 2005
    7.5
    High

    CVE-2005-1045

    Last Modified: 16 Apr 2026

    OpenText FirstClass 8.0 client does not properly sanitize strings before passing them to the Windows ShellExecute API, which allows remote attackers to execute arbitrary commands via a UNC path in a bookmark.

    Published: 12 Apr 2005
    5
    Medium

    CVE-2005-1050

    Last Modified: 16 Apr 2026

    The modload op in the Reviews module for PostNuke 0.760-RC3 allows remote attackers to obtain sensitive information via an invalid id parameter, which reveals the path in a PHP error message.

    Published: 12 Apr 2005
    5
    Medium

    CVE-2005-1052

    Last Modified: 16 Apr 2026

    Microsoft Outlook 2003 and Outlook Web Access (OWA) 2003 do not properly display comma separated addresses in the From field in an e-mail message, which could allow remote attackers to spoof e-mail addresses.

    Published: 12 Apr 2005
    7.5
    High

    CVE-2005-1058

    Last Modified: 16 Apr 2026

    Cisco IOS 12.2T, 12.3 and 12.3T, when processing an ISAKMP profile that specifies XAUTH authentication after Phase 1 negotiation, may not process certain attributes in the ISAKMP profile that specifies XAUTH, which allows remote attackers to bypass XAUTH and move to Phase 2 negotiations.

    Published: 12 Apr 2005
    2.1
    Low

    CVE-2005-1059

    Last Modified: 16 Apr 2026

    Linksys WET11 1.5.4 allows remote attackers to change the password without providing the original password via the data parameter to changepw.html.

    Published: 12 Apr 2005
    1.2
    Low

    CVE-2005-1066

    Last Modified: 16 Apr 2026

    Race condition in rpdump in Pine 4.62 and earlier allows local users to overwrite arbitrary files via a symlink attack.

    Published: 12 Apr 2005
    4.3
    Medium

    CVE-2005-1077

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.4.x allow remote attackers to inject arbitrary web script or HTML via (1) cds.php, (2) Guestbook-EN.pl, or (3) phonebook.php.

    Published: 12 Apr 2005
    4.3
    Medium

    CVE-2005-1085

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the control panel in aeDating 3.2 allows remote attackers to inject arbitrary web script or HTML.

    Published: 12 Apr 2005
    5
    Medium

    CVE-2004-0790

    Last Modified: 16 Apr 2026

    Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.

    Published: 12 Apr 2005
    7.5
    High

    CVE-2005-0390

    Last Modified: 16 Apr 2026

    Buffer overflow in the HTTP redirection capability in conn.c for Axel before 1.0b may allow remote attackers to execute arbitrary code.

    Published: 12 Apr 2005
    7.5
    High

    CVE-2005-0555

    Last Modified: 16 Apr 2026

    Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka "Content Advisor Memory Corruption Vulnerability."

    Published: 12 Apr 2005
    7.5
    High

    CVE-2005-0562

    Last Modified: 16 Apr 2026

    GIF file validation error in MSN Messenger 6.2 allows remote attackers in a user's contact list to execute arbitrary code via a GIF image with an improper height and width.

    Published: 12 Apr 2005
    7.2
    High

    CVE-2005-0610

    Last Modified: 16 Apr 2026

    Multiple symlink vulnerabilities in portupgrade before 20041226_2 in FreeBSD allow local users to (1) overwrite arbitrary files and possibly replace packages to execute arbitrary code via pkg_fetch, (2) overwrite arbitrary files via temporary files when portupgrade upgrades a port or package, or (3) create arbitrary zero-byte files via the pkgdb.fixme temporary file.

    Published: 12 Apr 2005
    5
    Medium

    CVE-2004-0791

    Last Modified: 16 Apr 2026

    Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.

    Published: 12 Apr 2005
    5.1
    Medium

    CVE-2005-0941

    Last Modified: 16 Apr 2026

    The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but process memory using 32 bit values, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a DOC document with certain length values, which leads to a heap-based buffer overflow.

    Published: 12 Apr 2005
    5
    Medium

    CVE-2005-1089

    Last Modified: 16 Apr 2026

    Unknown vulnerability in DC++ before 0.674 allows attackers to append data to arbitrary files.

    Published: 11 Apr 2005
    7.5
    High

    CVE-2005-1070

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in Invision Power Board 1.3.1 Final and earlier allows remote attackers to execute arbitrary SQL commands via the st parameter.

    Published: 11 Apr 2005
    3.7
    Low

    CVE-2005-1039

    Last Modified: 16 Apr 2026

    Race condition in Core Utilities (coreutils) 5.2.1, when (1) mkdir, (2) mknod, or (3) mkfifo is running with the -m switch, allows local users to modify permissions of other files.

    Published: 10 Apr 2005
    7.2
    High

    CVE-2005-1040

    Last Modified: 16 Apr 2026

    Multiple unknown vulnerabilities in netapplet in Novell Linux Desktop 9 allow local users to gain root privileges, related to "User input [being] passed to network scripts without verification."

    Published: 10 Apr 2005
    7.5
    High

    CVE-2005-1055

    Last Modified: 16 Apr 2026

    TowerBlog 0.6 and earlier stores the login data file under the web root, which allows remote attackers to obtain the MD5 checksums of the username and password via a direct request to the _dat/login file.

    Published: 10 Apr 2005
    4.6
    Medium

    CVE-2005-1064

    Last Modified: 16 Apr 2026

    The copy_symlink function in rsnapshot 1.2.0 and 1.1.x before 1.1.7 changes the ownership of files that a symlink points to rather than the symlink itself, which allows local users to obtain access to arbitrary files.

    Published: 10 Apr 2005
    7.8
    High

    CVE-2005-1036

    Last Modified: 16 Apr 2026

    FreeBSD 5.x to 5.4 on AMD64 does not properly initialize the IO permission bitmap used to allow user access to certain hardware, which allows local users to bypass intended access restrictions to cause a denial of service, obtain sensitive information, and possibly gain privileges.

    Published: 10 Apr 2005
    10
    Critical

    CVE-2005-1037

    Last Modified: 16 Apr 2026

    Unknown vulnerability in AIX 5.3.0, when configured as an NIS client, allows remote attackers to gain root privileges.

    Published: 10 Apr 2005
    7.1
    High

    CVE-2005-1021

    Last Modified: 16 Apr 2026

    Memory leak in Secure Shell (SSH) in Cisco IOS 12.0 through 12.3, when authenticating against a TACACS+ server, allows remote attackers to cause a denial of service (memory consumption) via an incorrect username or password.

    Published: 9 Apr 2005
    5
    Medium

    CVE-2005-1022

    Last Modified: 16 Apr 2026

    ColdFusion 6.1 Updater 1 places Java .class files under the web root in the /WEB-INF/cfclasses directory, which allows remote attackers to obtain sensitive information.

    Published: 9 Apr 2005
    4.3
    Medium

    CVE-2005-1023

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x to 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) min parameter to the Search module, (2) the categories parameter to the FAQ module, or (3) the ltr parameter to the Encyclopedia module. NOTE: the bid parameter issue in banners.php is already an item in CVE-2005-1000.

    Published: 9 Apr 2005
    5
    Medium

    CVE-2005-1028

    Last Modified: 16 Apr 2026

    PHP-Nuke 6.x through 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) index.php with the forum_admin parameter set, (2) the Surveys module, or (3) the Your_Account module, which reveals the path in a PHP error message.

    Published: 9 Apr 2005
    4.3
    Medium

    CVE-2005-1030

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Active Auction House allow remote attackers to inject arbitrary web script or HTML via the (1) ReturnURL, (2) password, (3) username parameter, (4) ReturnURL parameter to account.asp, (5) Table, (6) Title parameter to sendpassword.asp, or (7) itemid to watchthisitem.asp.

    Published: 9 Apr 2005
    5
    Medium

    CVE-2005-1031

    Last Modified: 16 Apr 2026

    RUNCMS 1.1A, and possibly other products based on e-Xoops (exoops), when "Allow custom avatar upload" is enabled, does not properly verify uploaded files, which allows remote attackers to upload arbitrary files.

    Published: 9 Apr 2005
    7.5
    High

    CVE-2005-1082

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in AzDGDatingPlatinum 1.1.0 allows remote attackers to execute arbitrary SQL commands via (1) the id parameter to view.php or (2) the from parameter to members/index.php.

    Published: 9 Apr 2005
    7.2
    High

    CVE-2005-1019

    Last Modified: 16 Apr 2026

    Buffer overflow in the getConfig function in Aeon 0.2a and earlier allows local users to gain privileges via a long HOME environment variable.

    Published: 9 Apr 2005
    7.1
    High

    CVE-2005-1020

    Last Modified: 16 Apr 2026

    Secure Shell (SSH) 2 in Cisco IOS 12.0 through 12.3 allows remote attackers to cause a denial of service (device reload) (1) via a username that contains a domain name when using a TACACS+ server to authenticate, (2) when a new SSH session is in the login phase and a currently logged in user issues a send command, or (3) when IOS is logging messages and an SSH session is terminated while the server is sending data.

    Published: 9 Apr 2005
    5
    Medium

    CVE-2005-1024

    Last Modified: 16 Apr 2026

    modules.php in PHP-Nuke 6.x to 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) my_headlines, (2) userinfo, or (3) search, which reveals the path in a PHP error message.

    Published: 9 Apr 2005
    7.5
    High

    CVE-2005-1026

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in SnailSource phpBB 2.0.x mods allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to dlman.php in DLMan Pro or (2) id parameter to links.php in Linkz Pro (aka LinksLinks Pro).

    Published: 9 Apr 2005
    4.3
    Medium

    CVE-2005-1027

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x through 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter in the Your_Account module, (2) avatarcategory parameter in the Your_Account module, or (3) lid parameter in the Downloads module.

    Published: 9 Apr 2005