CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2005-0950

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in FastStone 4in1 Browser 1.2 allows remote attackers to read arbitrary files via a (1) ... (triple dot) or (2) ..\ (dot dot backslash) in the URL.

    Published: 29 Mar 2005
    2.1
    Low

    CVE-2005-0923

    Last Modified: 16 Apr 2026

    The SmartScan feature in the Auto-Protect module for Symantec Norton AntiVirus 2004 and 2005, as also used in Internet Security 2004/2005 and System Works 2004/2005, allows attackers to cause a denial of service (CPU consumption and system crash) by renaming a file on a network share.

    Published: 29 Mar 2005
    2.1
    Low

    CVE-2005-0916

    Last Modified: 16 Apr 2026

    AIO in the Linux kernel 2.6.11 on the PPC64 or IA64 architectures with CONFIG_HUGETLB_PAGE enabled allows local users to cause a denial of service (system panic) via a process that executes the io_queue_init function but exits without running io_queue_release, which causes exit_aio and is_hugepage_only_range to fail.

    Published: 29 Mar 2005
    7.5
    High

    CVE-2005-0915

    Last Modified: 16 Apr 2026

    Webmasters-Debutants WD Guestbook 2.8 allows remote attackers to bypass authentication and perform certain administrator actions via a direct HTTP POST request to (1) ajout_admin2.php or (2) suppr.php.

    Published: 29 Mar 2005
    7.5
    High

    CVE-2005-0946

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in phpCoin 1.2.1b and earlier allows remote attackers to execute arbitrary SQL commands via the (1) term/keywords field on the search page, (2) username or (3) e-mail field on the forgot password page, or (4) domain name on the ordering new package page.

    Published: 29 Mar 2005
    7.5
    High

    CVE-2005-0932

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in phpCOIN 1.2.1b and earlier allow remote attackers to execute arbitrary SQL commands (1) via the search engine, (2) the username or email fields in the "forgotten password" feature, or (3) the domain name in a package order.

    Published: 29 Mar 2005
    5
    Medium

    CVE-2005-0936

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in products1h.php in ESMI PayPal Storefront allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 29 Mar 2005
    7.5
    High

    CVE-2005-0935

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in ESMI PayPal Storefront allow remote attackers to execute arbitrary SQL commands via the (1) idpages parameter to pages.php or the (2) id2 parameter to products1.php.

    Published: 29 Mar 2005
    4.3
    Medium

    CVE-2005-0934

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in WackoWiki R4 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 29 Mar 2005
    5
    Medium

    CVE-2005-0933

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in auxpage.php for phpCOIN 1.2.1b and earlier allows remote attackers to read arbitrary files via the page parameter.

    Published: 29 Mar 2005
    7.5
    High

    CVE-2005-0897

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in catalog.php in E-Store Kit-2 PayPal Edition allows remote attackers to execute arbitrary PHP code by modifying the menu and main parameters to reference a URL on a remote web server that contains the code.

    Published: 29 Mar 2005
    2.1
    Low

    CVE-2005-0899

    Last Modified: 16 Apr 2026

    AS/400 running OS400 5.2 installs and enables LDAP by default, which allows remote authenticated users to obtain OS/400 user profiles by performing a search.

    Published: 29 Mar 2005
    4.3
    Medium

    CVE-2005-0901

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in NukeBookmarks 0.6 for PHP-Nuke allow remote attackers to inject arbitrary web script or HTML via the (1) catname, (2) markname, (3) comment, or (4) category parameter.

    Published: 29 Mar 2005
    7.5
    High

    CVE-2005-0902

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in marks.php in NukeBookmarks 0.6 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Published: 29 Mar 2005
    2.6
    Low

    CVE-2005-0903

    Last Modified: 16 Apr 2026

    Buffer overflow in QuickTime PictureViewer 6.5.1 allows remote attackers to cause a denial of service (application crash) via a JPEG file with crafted Huffman Table (marker DHT) data.

    Published: 29 Mar 2005
    4.3
    Medium

    CVE-2005-0896

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in review.php in phpMyDirectory 10.1.3-rel allow remote attackers to inject arbitrary web script or HTML via the (1) subcat, (2) page, or (3) subsubcat parameter.

    Published: 29 Mar 2005
    7.5
    High

    CVE-2005-0909

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in shoutact.php for TKai's Shoutbox allows remote attackers to execute arbitrary PHP code via the query parameter.

    Published: 29 Mar 2005
    4.3
    Medium

    CVE-2005-0910

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in exoops allow remote attackers to inject arbitrary web script or HTML via (1) the sortdays parameter to viewforum.php or (2) the viewcat parameter to index.php.

    Published: 29 Mar 2005
    7.5
    High

    CVE-2005-0913

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the regex_replace modifier (modifier.regex_replace.php) in Smarty before 2.6.8 allows attackers to execute arbitrary PHP code.

    Published: 29 Mar 2005
    7.5
    High

    CVE-2005-0917

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index_header.php for EncapsBB 0.3.2_fixed, and possibly other versions, allows remote attackers to execute arbitrary PHP code via the root parameter.

    Published: 29 Mar 2005
    4.3
    Medium

    CVE-2005-0919

    Last Modified: 16 Apr 2026

    Adventia Chat 3.1 and Server Pro 3.0 allows remote attackers to inject arbitrary web script or HTML into the chat space, which leaves other users vulnerable to cross-site scripting (XSS) attacks.

    Published: 29 Mar 2005
    7.5
    High

    CVE-2005-0920

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Bugtracker.NET 2.0.1 allow remote attackers to execute arbitrary SQL commands via unknown vectors.

    Published: 29 Mar 2005
    4.3
    Medium

    CVE-2005-0925

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in login.asp for Ublog Reload 1.0 through 1.0.4 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Published: 29 Mar 2005
    5.1
    Medium

    CVE-2005-0926

    Last Modified: 16 Apr 2026

    Buffer overflow in Sylpheed before 1.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attachments with MIME-encoded file names.

    Published: 29 Mar 2005
    10
    Critical

    CVE-2005-0927

    Last Modified: 16 Apr 2026

    Unknown vulnerability in subs.pl for WebAPP 0.9.9 through 0.9.9.2 has unknown impact and attack vectors, probably involving shell metacharacters or .. sequences.

    Published: 29 Mar 2005
    7.5
    High

    CVE-2005-0929

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in PhotoPost PHP Pro 5.x may allow remote attackers to execute arbitrary SQL commands via (1) the sl parameter to showmembers.php or (2) the photo parameter to showphoto.php.

    Published: 29 Mar 2005
    4.3
    Medium

    CVE-2005-0930

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in message.php in Chatness 2.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the user field or (2) the message parameter to message.php.

    Published: 29 Mar 2005
    3.6
    Low

    CVE-2005-0894

    Last Modified: 16 Apr 2026

    OpenmosixCollector and OpenMosixView in OpenMosixView 1.5 allow local users to overwrite or delete arbitrary files via a symlink attack on (1) temporary files in the openmosixcollector directory or (2) nodes.tmp.

    Published: 29 Mar 2005
    7.6
    High

    CVE-2005-0893

    Last Modified: 16 Apr 2026

    modes.c in smail 3.2.0.120 implements signal handlers with certain unsafe library calls, which may allow attackers to execute arbitrary code via signal handler race conditions, possibly using xmalloc.

    Published: 29 Mar 2005
    4.6
    Medium

    CVE-2005-0763

    Last Modified: 16 Apr 2026

    Buffer overflow in Midnight Commander (mc) 4.5.55 and earlier may allow attackers to execute arbitrary code.

    Published: 29 Mar 2005
    7.5
    High

    CVE-2005-0911

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in exoops may allow remote attackers to execute arbitrary SQL commands via (1) the viewcat parameter to index.php or (2) the artid parameter in the viewarticle action for index.php.

    Published: 28 Mar 2005
    4.3
    Medium

    CVE-2005-0908

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Valdersoft Shopping Cart 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the lang parameter to index.php or (2) the searchTopCategoryID parameter to search_result.php.

    Published: 28 Mar 2005
    10
    Critical

    CVE-2005-0892

    Last Modified: 16 Apr 2026

    Buffer overflow in smail 3.2.0.120 allows remote attackers or local users to execute arbitrary code via a long string in the MAIL FROM command and possibly other SMTP commands.

    Published: 28 Mar 2005
    7.5
    High

    CVE-2005-0469

    Last Modified: 16 Apr 2026

    Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands.

    Published: 28 Mar 2005
    5
    Medium

    CVE-2005-0967

    Last Modified: 16 Apr 2026

    Gaim 1.2.0 allows remote attackers to cause a denial of service (application crash) via a malformed file transfer request to a Jabber user, which leads to an out-of-bounds read.

    Published: 28 Mar 2005
    7.5
    High

    CVE-2005-0468

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the env_opt_add function in telnet.c for various BSD-based Telnet clients allows remote attackers to execute arbitrary code via responses that contain a large number of characters that require escaping, which consumers more memory than allocated.

    Published: 28 Mar 2005
    2.1
    Low

    CVE-2005-3105

    Last Modified: 16 Apr 2026

    The mprotect code (mprotect.c) in Linux 2.6 on Itanium IA64 Montecito processors does not properly maintain cache coherency as required by the architecture, which allows local users to cause a denial of service and possibly corrupt data by modifying PTE protections.

    Published: 28 Mar 2005
    4.3
    Medium

    CVE-2005-0914

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in CPG Dragonfly 9.0.2.0 allow remote attackers to inject arbitrary web script or HTML via (1) the profile parameter to index.php or (2) the cat parameter.

    Published: 26 Mar 2005
    7.5
    High

    CVE-2005-0879

    Last Modified: 16 Apr 2026

    PHP remote file include vulnerability in (1) content.php and (2) index.php for Vortex Portal allows remote attackers to execute arbitrary PHP code via a URL in the act parameter.

    Published: 26 Mar 2005
    4.3
    Medium

    CVE-2005-0872

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in calendar_scheduler.php in the Topic Calendar 1.0.1 module for phpBB allows remote attackers to inject arbitrary web script or HTML via the start parameter.

    Published: 26 Mar 2005
    5
    Medium

    CVE-2005-0871

    Last Modified: 16 Apr 2026

    calendar_scheduler.php in Topic Calendar 1.0.1 module for phpBB, when running on a Microsoft IIS server, allows remote attackers to obtain sensitive information via invalid parameters, which reveal the path in an error message.

    Published: 26 Mar 2005
    7.5
    High

    CVE-2005-0868

    Last Modified: 16 Apr 2026

    AS/400 Telnet 5250 terminal emulation clients, as implemented by (1) IBM client access, (2) Bosanova, (3) PowerTerm, (4) Mochasoft, and possibly other emulations, allows malicious AS/400 servers to execute arbitrary commands via a STRPCO (Start PC Organizer) command followed by STRPCCMD (Start PC command), as demonstrated by creating a backdoor account using REXEC.

    Published: 26 Mar 2005
    5
    Medium

    CVE-2005-0869

    Last Modified: 16 Apr 2026

    phpSysInfo 2.3 allows remote attackers to obtain sensitive information via a direct request to (1) class.OpenBSD.inc.php, (2) class.NetBSD.inc.php, (3) class.FreeBSD.inc.php, (4) class.Darwin.inc.php, (5) XPath.class.php, (6) system_header.php, or (7) system_footer.php, which reveal the path in a PHP error message.

    Published: 26 Mar 2005
    4.3
    Medium

    CVE-2005-0870

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in phpSysInfo 2.3, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) sensor_program parameter to index.php, (2) text[language], (3) text[template], or (4) hide_picklist parameter to system_footer.php.

    Published: 26 Mar 2005
    2.1
    Low

    CVE-2005-0866

    Last Modified: 16 Apr 2026

    cdrecord before 4:2.0, when DEBUG is enabled, allows local users to overwrite arbitrary files via a symlink attack on temporary files.

    Published: 26 Mar 2005
    4.3
    Medium

    CVE-2005-0873

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in test.jsp in Oracle Reports Server 10g (9.0.4.3.3) allow remote attackers to inject arbitrary web script or HTML via the (1) desname or (2) repprod parameter.

    Published: 26 Mar 2005
    5
    Medium

    CVE-2005-0874

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the (1) AIM, (2) MSN, (3) RSS, and other plug-ins for Trillian 2.0 allow remote web servers to cause a denial of service (application crash) via a long string in an HTTP 1.1 response header.

    Published: 26 Mar 2005
    5
    Medium

    CVE-2005-0875

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the Yahoo plug-in for Trillian 2.0, 3.0, and 3.1 allow remote web servers to cause a denial of service (application crash) via a long string in an HTTP 1.1 response header.

    Published: 26 Mar 2005
    5
    Medium

    CVE-2005-0876

    Last Modified: 16 Apr 2026

    Off-by-one buffer overflow in Dnsmasq before 2.21 may allow attackers to execute arbitrary code via the DHCP lease file.

    Published: 26 Mar 2005
    7.5
    High

    CVE-2005-0877

    Last Modified: 16 Apr 2026

    Dnsmasq before 2.21 allows remote attackers to poison the DNS cache via answers to queries that were not made by Dnsmasq.

    Published: 26 Mar 2005