CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2005-0968

    Last Modified: 16 Apr 2026

    Computer Associates (CA) eTrust Intrusion Detection 3.0 allows remote attackers to cause a denial of service via large size values that are not properly validated before calling the CPImportKey function in the Crypto API.

    Published: 5 Apr 2005
    5
    Medium

    CVE-2005-0978

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the Object Push service in IVT BlueSoleil 1.4 allows remote attackers to upload arbitrary files via a .. (dot dot) in a PUSH command.

    Published: 5 Apr 2005
    5
    Medium

    CVE-2005-0983

    Last Modified: 16 Apr 2026

    Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, which is not properly truncated and causes the engine to process the remaining data as if it were network data.

    Published: 5 Apr 2005
    5
    Medium

    CVE-2005-0984

    Last Modified: 16 Apr 2026

    Buffer overflow in the G_Printf function in Star Wars Jedi Knight: Jedi Academy 1.011 and earlier allows remote attackers to execute arbitrary code via a long message using commands such as (1) say and (2) tell.

    Published: 5 Apr 2005
    10
    Critical

    CVE-2005-0708

    Last Modified: 16 Apr 2026

    The sendfile system call in FreeBSD 4.8 through 4.11 and 5 through 5.4 can transfer portions of kernel memory if a file is truncated while it is being sent, which could allow remote attackers to obtain sensitive information.

    Published: 5 Apr 2005
    4.3
    Medium

    CVE-2005-0982

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Yet Another Forum.net 0.9.9 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) location, or (3) Subject field.

    Published: 5 Apr 2005
    2.1
    Low

    CVE-2005-0387

    Last Modified: 16 Apr 2026

    remstats 1.0.13 and earlier, when processing uptime data, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.

    Published: 4 Apr 2005
    7.5
    High

    CVE-2005-0388

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the remoteping service in remstats 1.0.13 and earlier allows remote attackers to execute arbitrary commands "due to missing input sanitising."

    Published: 4 Apr 2005
    3.7
    Low

    CVE-2005-0988

    Last Modified: 16 Apr 2026

    Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.

    Published: 4 Apr 2005
    7.5
    High

    CVE-2005-0944

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Microsoft Jet DB engine (msjet40.dll) 4.00.8618.0, related to insufficient data validation, allows remote attackers to execute arbitrary code via a crafted mdb file.

    Published: 3 Apr 2005
    4.3
    Medium

    CVE-2005-0945

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in ACS Blog 1.1.1 allows remote attackers to inject arbitrary web script or HTML via onmouseover or onload events in (1) img, (2) link, or (3) mail tags.

    Published: 3 Apr 2005
    7.5
    High

    CVE-2005-0947

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in auxpage.php in phpCoin 1.2.1b and earlier allows remote attackers to read and execute arbitrary files via a .. (dot dot) in the page parameter.

    Published: 3 Apr 2005
    7.5
    High

    CVE-2005-0948

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in ad_click.asp for PortalApp allows remote attackers to execute arbitrary SQL commands via the banner_id parameter.

    Published: 3 Apr 2005
    5
    Medium

    CVE-2005-0952

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in pafiledb.php in PaFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 3 Apr 2005
    5
    Medium

    CVE-2005-0954

    Last Modified: 16 Apr 2026

    Windows Explorer and Internet Explorer in Windows 2000 SP1 allows remote attackers to cause a denial of service (CPU consumption) via a malformed Windows Metafile (WMF) file.

    Published: 3 Apr 2005
    Unknown

    CVE-2005-0951

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: this candidate was created as a result of an analysis error for a researcher advisory for an issue that already existed. It stated an incorrect parameter, which was not part of the vulnerability at all. Notes: CVE users should not reference this candidate at all

    Published: 3 Apr 2005
    4.3
    Medium

    CVE-2005-0961

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Horde 3.0.4 before 3.0.4-RC2 allows remote attackers to inject arbitrary web script or HTML via the parent frame title.

    Published: 3 Apr 2005
    4.6
    Medium

    CVE-2005-0964

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Kerio Personal Firewall 4.1.2 and earlier allows local users to bypass firewall rules via a malicious process that impersonates a legitimate process that has fewer restrictions.

    Published: 3 Apr 2005
    4.3
    Medium

    CVE-2005-0949

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in content.asp in Iatek PortalApp allow remote attackers to inject arbitrary web script or HTML via the (1) contenttype or (2) keywords parameter.

    Published: 3 Apr 2005
    7.5
    High

    CVE-2005-0958

    Last Modified: 16 Apr 2026

    Format string vulnerability in the log_do function in log.c for YepYep mtftpd 0.0.3, when the statistics option is enabled, allows remote attackers to execute arbitrary code via the CWD command.

    Published: 3 Apr 2005
    5
    Medium

    CVE-2005-0960

    Last Modified: 16 Apr 2026

    Multiple vulnerabilities in the SACK functionality in (1) tcp_input.c and (2) tcp_usrreq.c OpenBSD 3.5 and 3.6 allow remote attackers to cause a denial of service (memory exhaustion or system crash).

    Published: 3 Apr 2005
    2.1
    Low

    CVE-2005-0963

    Last Modified: 16 Apr 2026

    An error in the Toshiba ACPI BIOS 1.6 causes the BIOS to only examine the first slot in the Master Boot Record (MBR) table for an active partition, which prevents the system from booting even though the MBR is not malformed. NOTE: it has been debated as to whether or not this issue poses a security vulnerability, since administrative privileges would be required, and other DoS attacks are possible with such privileges.

    Published: 3 Apr 2005
    5
    Medium

    CVE-2005-0942

    Last Modified: 16 Apr 2026

    The XP Server process (xp_server) in Sybase Adaptive Server Enterprise (ASE) XP Server 12.x before 12.5.3 ESD#1 allows attackers to cause a denial of service (process crash) via malformed data sent to the XP Server TCP port.

    Published: 3 Apr 2005
    7.5
    High

    CVE-2005-0956

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in InterAKT MX Kart 1.1.2 allow remote attackers to execute arbitrary SQL commands via the (1) idp, (2) id_ctg, or (3) id_man parameter.

    Published: 3 Apr 2005
    7.5
    High

    CVE-2005-0959

    Last Modified: 16 Apr 2026

    Buffer overflow in the mt_do_dir function in YepYep mtftpd 0.0.3 may allow attackers to execute arbitrary code via a long path.

    Published: 3 Apr 2005
    7.5
    High

    CVE-2005-0955

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in InterAKT MX Shop 1.1.1 allows remote attackers to execute arbitrary SQL commands via the id_ctg parameter.

    Published: 3 Apr 2005
    7.5
    High

    CVE-2005-0962

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php for Lighthouse Squirrelcart allows remote attackers to execute arbitrary SQL commands via the (1) crn parameter in a show action or (2) rn parameter in a show_detail action.

    Published: 3 Apr 2005
    5
    Medium

    CVE-2005-0965

    Last Modified: 16 Apr 2026

    The gaim_markup_strip_html function in Gaim 1.2.0, and possibly earlier versions, allows remote attackers to cause a denial of service (application crash) via a string that contains malformed HTML, which causes an out-of-bounds read.

    Published: 1 Apr 2005
    6.4
    Medium

    CVE-2005-0966

    Last Modified: 16 Apr 2026

    The IRC protocol plugin in Gaim 1.2.0, and possibly earlier versions, allows (1) remote attackers to inject arbitrary Gaim markup via irc_msg_kick, irc_msg_mode, irc_msg_part, irc_msg_quit, (2) remote attackers to inject arbitrary Pango markup and pop up empty dialog boxes via irc_msg_invite, or (3) malicious IRC servers to cause a denial of service (application crash) by injecting certain Pango markup into irc_msg_badmode, irc_msg_banned, irc_msg_unknown, irc_msg_nochan functions.

    Published: 1 Apr 2005
    4.3
    Medium

    CVE-2005-0386

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in network.cgi in mailreader before 2.3.29 earlier allows remote attackers to inject arbitrary web script or HTML via MIME text/enriched or text/richtext messages.

    Published: 31 Mar 2005
    7.5
    High

    CVE-2005-0957

    Last Modified: 16 Apr 2026

    Bay Technical Associates RPC-3 Telnet Host 3.05 allows remote attackers to bypass authentication by pressing the escape and enter keys at the username prompt.

    Published: 31 Mar 2005
    5
    Medium

    CVE-2005-0525

    Last Modified: 16 Apr 2026

    The php_next_marker function in image.c for PHP 4.2.2, 4.3.9, 4.3.10 and 5.0.3, as reachable by the getimagesize PHP function, allows remote attackers to cause a denial of service (infinite loop) via a JPEG image with an invalid marker value, which causes a negative length value to be passed to php_stream_seek.

    Published: 31 Mar 2005
    5
    Medium

    CVE-2005-0524

    Last Modified: 16 Apr 2026

    The php_handle_iff function in image.c for PHP 4.2.2, 4.3.9, 4.3.10 and 5.0.3, as reachable by the getimagesize PHP function, allows remote attackers to cause a denial of service (infinite loop) via a -8 size value.

    Published: 31 Mar 2005
    2.1
    Low

    CVE-2005-0990

    Last Modified: 16 Apr 2026

    unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file.

    Published: 31 Mar 2005
    7.5
    High

    CVE-2005-1042

    Last Modified: 16 Apr 2026

    Integer overflow in the exif_process_IFD_TAG function in exif.c in PHP before 4.3.11 may allow remote attackers to execute arbitrary code via an IFD tag that leads to a negative byte count.

    Published: 31 Mar 2005
    5
    Medium

    CVE-2005-1043

    Last Modified: 16 Apr 2026

    exif.c in PHP before 4.3.11 allows remote attackers to cause a denial of service (memory consumption and crash) via an EXIF header with a large IFD nesting level, which causes significant stack recursion.

    Published: 31 Mar 2005
    4.6
    Medium

    CVE-2005-1194

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the ieee_putascii function for nasm 0.98 and earlier allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2004-1287.

    Published: 31 Mar 2005
    5
    Medium

    CVE-2005-0943

    Last Modified: 16 Apr 2026

    Cisco VPN 3000 series Concentrator running firmware 4.1.7.A and earlier allows remote attackers to cause a denial of service (device reload or drop user connection) via a crafted HTTPS packet.

    Published: 30 Mar 2005
    5
    Medium

    CVE-2005-0938

    Last Modified: 16 Apr 2026

    Ublog Reload 1.0 through 1.0.4 stores ublogreload.mdb under the web root, which allows remote attackers to read usernames and hashed passwords via a direct request to ublogreload.mdb.

    Published: 30 Mar 2005
    3.7
    Low

    CVE-2005-0953

    Last Modified: 16 Apr 2026

    Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by bzip2 after the decompression is complete.

    Published: 30 Mar 2005
    7.5
    High

    CVE-2005-0931

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in The Includer 1.0 and 1.1 allows remote attackers to execute arbitrary PHP code.

    Published: 29 Mar 2005
    4.3
    Medium

    CVE-2005-0928

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 5.x allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) password, (3) ppuser, (4) sort, or (5) si parameters to showgallery.php, the (6) ppuser, (7) sort, or (8) si parameters to showmembers.php, or (9) the photo parameter to slideshow.php.

    Published: 29 Mar 2005
    4.3
    Medium

    CVE-2005-0924

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Adventia E-Data 2.0 allows remote attackers to inject arbitrary web script or HTML via a query keyword.

    Published: 29 Mar 2005
    5
    Medium

    CVE-2005-0922

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the Auto-Protect module in Symantec Norton AntiVirus 2004 and 2005, as also used in Internet Security 2004/2005 and System Works 2004/2005, allows attackers to cause a denial of service (system hang or crash) by triggering a scan of a certain file type.

    Published: 29 Mar 2005
    4.6
    Medium

    CVE-2005-0921

    Last Modified: 16 Apr 2026

    Microsoft Outlook 2002 Connector for IBM Lotus Domino 2.0 allows local users to save passwords and login credentials locally, even when password caching is disabled by a group policy.

    Published: 29 Mar 2005
    2.1
    Low

    CVE-2005-0904

    Last Modified: 16 Apr 2026

    Remote Desktop in Windows XP SP1 does not verify the "Force shutdown from a remote system" setting, which allows remote attackers to shut down the system by executing TSShutdn.exe.

    Published: 29 Mar 2005
    5
    Medium

    CVE-2005-0895

    Last Modified: 16 Apr 2026

    Netcomm 1300NB DSL Modem allows remote attackers to cause a denial of service (device hang) via a large number of ping packets.

    Published: 29 Mar 2005
    2.6
    Low

    CVE-2005-0905

    Last Modified: 16 Apr 2026

    Maxthon 1.2.0 allows remote malicious web sites to obtain potentially sensitive data from the search bar via the m2_search_text property.

    Published: 29 Mar 2005
    7.5
    High

    CVE-2005-0906

    Last Modified: 16 Apr 2026

    Buffer overflow in a player logging function in the Tincat network library 2.x before 2.0.28, as used in games such as Sacred and The Settlers: Heritage of Kings, allows remote attackers to execute arbitrary code.

    Published: 29 Mar 2005
    7.5
    High

    CVE-2005-0907

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Valdersoft Shopping Cart 3.0 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to category.php, (2) the id parameter to item.php, (3) the lang parameter to index.php, (4) the searchQuery parameter to search_result.php, (5) or the searchTopCategoryID parameter to search_result.php.

    Published: 29 Mar 2005