CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2005-0882

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in admincore.php in BirdBlog before 1.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) userid or (2) userpw parameters.

    Published: 26 Mar 2005
    7.5
    High

    CVE-2005-0884

    Last Modified: 16 Apr 2026

    DigitalHive 2.0 allows remote attackers to re-install the product by directly accessing the install script.

    Published: 26 Mar 2005
    4.3
    Medium

    CVE-2005-0885

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in XMB Forum 1.9.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Mood or (2) "Send To" fields.

    Published: 26 Mar 2005
    4.3
    Medium

    CVE-2005-0886

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Invision Power Board 2.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an HTTP POST request.

    Published: 26 Mar 2005
    5
    Medium

    CVE-2005-0880

    Last Modified: 16 Apr 2026

    content.php in Vortex Portal allows remote attackers to obtain sensitive information via an invalid act parameter, which leaks the full pathname in a PHP error message.

    Published: 26 Mar 2005
    7.5
    High

    CVE-2005-0890

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Dream4 Koobi CMS 4.2.3 allows remote attackers to execute arbitrary SQL commands via the area parameter.

    Published: 26 Mar 2005
    4.3
    Medium

    CVE-2005-0888

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in functions.inc.php for Double Choco Latte 0.9.4.3 allow remote attackers to inject arbitrary web script or HTML via the (1) class or (2) method name.

    Published: 26 Mar 2005
    4.3
    Medium

    CVE-2005-0898

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in downloadform.php in E-Store Kit-2 PayPal Edition allows remote attackers to inject arbitrary web script or HTML via the txn_id parameter.

    Published: 26 Mar 2005
    5
    Medium

    CVE-2005-0900

    Last Modified: 16 Apr 2026

    marks.php in NukeBookmarks 0.6 for PHP-Nuke allows remote attackers to obtain sensitive information via an invalid (1) file or (2) category parameter, which reveal the path in an error message.

    Published: 26 Mar 2005
    7.5
    High

    CVE-2005-0891

    Last Modified: 16 Apr 2026

    Double free vulnerability in gtk 2 (gtk2) before 2.2.4 allows remote attackers to cause a denial of service (crash) via a crafted BMP image.

    Published: 26 Mar 2005
    7.5
    High

    CVE-2005-0887

    Last Modified: 16 Apr 2026

    Eval injection vulnerability in Double Choco Latte before 0.9.4.3 allows remote attackers to execute arbitrary PHP code via the menuAction variable in (1) functions.inc.php or (2) main.php, which causes code to be injected into an eval statement.

    Published: 24 Mar 2005
    4.3
    Medium

    CVE-2005-0863

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in PHPOpenChat v3.x allows remote attackers to inject arbitrary web script or HTML via (1) the chatter parameter to regulars.php or (2) the chatter, chatter1, chatter2, chatter3, or chatter4 parameters to register.php.

    Published: 24 Mar 2005
    7.5
    High

    CVE-2005-0841

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in (1) people.php, (2) track.php, (3) edit.php, (4) document.php, (5) census.php, (6) passthru.php and possibly other php files in phpMyFamily 1.4.0 allows remote attackers to execute arbitrary SQL commands, as demonstrated via (1) the person parameter to people.php or (2) the Login field.

    Published: 24 Mar 2005
    4.3
    Medium

    CVE-2005-0842

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) _i or (2) _c parameter.

    Published: 24 Mar 2005
    5
    Medium

    CVE-2005-0843

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in search.php in Phorum 5.0.14a allows remote attackers to perform HTTP Response Splitting attacks via the body parameter, which is included in the resulting Location header.

    Published: 24 Mar 2005
    4.6
    Medium

    CVE-2005-0844

    Last Modified: 16 Apr 2026

    Nortel VPN client 5.01 stores the cleartext password in the memory of the Extranet.exe process, which could allow local users to obtain sensitive information.

    Published: 24 Mar 2005
    5
    Medium

    CVE-2005-0845

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the Webmail interface in SurgeMail 2.2g3 allows remote authenticated users to write arbitrary files or directories via a .. (dot dot) in the attach_id parameter.

    Published: 24 Mar 2005
    4.3
    Medium

    CVE-2005-0846

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the email auto-reply message in SurgeMail 2.2g3 allow remote attackers to inject arbitrary web script or HTML via the (1) message subject or (2) message header field.

    Published: 24 Mar 2005
    5
    Medium

    CVE-2005-0851

    Last Modified: 16 Apr 2026

    FileZilla FTP server before 0.9.6, when using MODE Z (zlib compression), allows remote attackers to cause a denial of service (infinite loop) via certain file uploads or directory listings.

    Published: 24 Mar 2005
    2.1
    Low

    CVE-2005-0852

    Last Modified: 16 Apr 2026

    Microsoft Windows XP SP1 allows local users to cause a denial of service (system crash) via an empty datagram to a raw IP over IP socket (IP protocol 4), as originally demonstrated using code in Python 2.3.

    Published: 24 Mar 2005
    5
    Medium

    CVE-2005-0853

    Last Modified: 16 Apr 2026

    betaparticle blog (bp blog) stores the database under the web root, which allows remote attackers to obtain sensitive information via a direct request to (1) dbBlogMX.mdb for versions before 3.0, or (2) Blog.mdb for versions 3.0 and later. NOTE: it was later reported that vector 2 also affects versions 6.0 through 9.0.

    Published: 24 Mar 2005
    7.5
    High

    CVE-2005-0854

    Last Modified: 16 Apr 2026

    betaparticle blog (bp blog), posisbly before version 4, allows remote attackers to bypass authentication and (1) upload files via a direct request to upload.asp or (2) delete files via a direct request to myFiles.asp.

    Published: 24 Mar 2005
    7.5
    High

    CVE-2005-0858

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in CoolForum 0.8 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to entete.php or (2) the login parameter to register.php.

    Published: 24 Mar 2005
    7.5
    High

    CVE-2005-0859

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the tpath parameter to (1) headlines.php or (2) news.php. NOTE: some sources have reported the "dir" parameter as being affected; however, this is likely a cut-and-paste error from the wrong section of the original vulnerability report. Also, the news.php version was later reported to be in 1.12 through 1.14.

    Published: 24 Mar 2005
    7.5
    High

    CVE-2005-0860

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in TRG News Script 3.0 allows remote attackers to execute arbitrary PHP code via the dir parameter to (1) article.php, (2) authorall.php, (3) comment.php, (4) display.php, or (5) displayall.php.

    Published: 24 Mar 2005
    7.5
    High

    CVE-2005-0861

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in DeleGate before 8.11.1 may allow attackers to cause a denial of service or execute arbitrary code, possibly due to "overflows on arrays."

    Published: 24 Mar 2005
    7.5
    High

    CVE-2005-0862

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PHPOpenChat 3.0.1 and earlier allow remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter to (1) poc_loginform.php or (2) phpbb/poc.php, the poc_root_path parameter to (3) phpbb/poc.php, (4) phpnuke/ENGLISH_poc.php, (5) phpnuke/poc.php, or (6) yabbse/poc.php, or (7) the sourcedir parameter to yabbse/poc.php.

    Published: 24 Mar 2005
    4.3
    Medium

    CVE-2005-0857

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in avatar.php for CoolForum 0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the img parameter.

    Published: 24 Mar 2005
    7.5
    High

    CVE-2005-0865

    Last Modified: 16 Apr 2026

    Samsung ADSL Modem SMDK8947v1.2 uses default passwords for the (1) root, (2) admin, or (3) user users, which allows remote attackers to gain privileges via Telnet or an HTTP request to adsl.cgi.

    Published: 24 Mar 2005
    4.3
    Medium

    CVE-2005-0889

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php for Dream4 Koobi CMS 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the area parameter.

    Published: 24 Mar 2005
    7.5
    High

    CVE-2005-0912

    Last Modified: 16 Apr 2026

    Unknown vulnerabilities in deplate before 0.7.2 have unknown impact, possibly involving elements.rb.

    Published: 24 Mar 2005
    5
    Medium

    CVE-2005-0848

    Last Modified: 16 Apr 2026

    Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote attackers to cause a denial of service via an empty UDP packet to the server, which cannot detect that a new packet has arrived using the socket ioctl.

    Published: 24 Mar 2005
    5
    Medium

    CVE-2005-0849

    Last Modified: 16 Apr 2026

    Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote attackers to cause a denial of service (crash from invalid memory access) via a malformed join packet with values that cause the server to copy more memory than was actually provided in the packet.

    Published: 24 Mar 2005
    5
    Medium

    CVE-2005-0850

    Last Modified: 16 Apr 2026

    FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename containing an MS-DOS device name such as CON, NUL, COM1, LPT1, and others.

    Published: 24 Mar 2005
    10
    Critical

    CVE-2005-0855

    Last Modified: 16 Apr 2026

    CoolForum 0.8.1 beta and earlier allows remote attackers to obtain sensitive path information via direct requests to (1) entete.php, (2) profile_accueil.php, (3) profile_mdp.php, (4) profile_notify.php, (5) profile_options.php, (6) profile_perso.php, (7) profile_pm.php, or (8) readannonce.php, which leaks the full pathname in a PHP error message.

    Published: 24 Mar 2005
    5
    Medium

    CVE-2005-0864

    Last Modified: 16 Apr 2026

    The Boa web server, as used in Samsung ADSL Modem SMDK8947v1.2 and possibly other products, allows remote attackers to read arbitrary files via a full pathname in the HTTP request.

    Published: 24 Mar 2005
    7.5
    High

    CVE-2005-0856

    Last Modified: 16 Apr 2026

    CoolForum 0.8.1 beta and earlier allows remote attackers to manipulate SQL commands via certain requests to (1) alert.php or (2) viewip.php, possibly due to a SQL injection vulnerability.

    Published: 24 Mar 2005
    7.5
    High

    CVE-2005-0418

    Last Modified: 16 Apr 2026

    Argument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06, on Mac OS X, allows untrusted applications to gain privileges via the value parameter of a property tag in a JNLP file. NOTE: it is highly likely that this item will be MERGED with CVE-2005-0836.

    Published: 24 Mar 2005
    5
    Medium

    CVE-2005-0847

    Last Modified: 16 Apr 2026

    Code Ocean FTP server 1.0 allows remote attackers to cause a denial of service via a large number of connections.

    Published: 24 Mar 2005
    7.2
    High

    CVE-2005-0750

    Last Modified: 16 Apr 2026

    The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local users to gain privileges via (1) socket or (2) socketpair call with a negative protocol value.

    Published: 24 Mar 2005
    7.5
    High

    CVE-2005-1046

    Last Modified: 16 Apr 2026

    Buffer overflow in the kimgio library for KDE 3.4.0 allows remote attackers to execute arbitrary code via a crafted PCX image file.

    Published: 24 Mar 2005
    5.5
    Medium

    CVE-2005-0824

    Last Modified: 16 Apr 2026

    The internal_dump function in Mathopd before 1.5p5, and 1.6x before 1.6b6 BETA, when Mathopd is running with the -n option, allows local users to overwrite arbitrary files via a symlink attack on dump files that are triggered by a SIGWINCH signal.

    Published: 23 Mar 2005
    Unknown

    CVE-2005-0840

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-0706. Reason: This candidate is a duplicate of CVE-2005-0706. Notes: All CVE users should reference CVE-2005-0706 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 23 Mar 2005
    4.3
    Medium

    CVE-2005-0878

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in MercuryBoard before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the title field of a PM (private message).

    Published: 23 Mar 2005
    4.3
    Medium

    CVE-2005-0881

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in articles.newcomment for Interspire ArticleLive 2005 allows remote attackers to inject arbitrary web script or HTML via the Articleld parameter.

    Published: 23 Mar 2005
    4.3
    Medium

    CVE-2005-0883

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in base.php for DigitalHive 2.0 allow remote attackers to inject arbitrary web script or HTML via (1) the mt parameter to the membres.php page or (2) the -afs-1- query string to the msg.php page.

    Published: 23 Mar 2005
    Unknown

    CVE-2005-0389

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-0814. Reason: This candidate is a duplicate of CVE-2005-0814. Notes: All CVE users should reference CVE-2005-0814 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 23 Mar 2005
    5.1
    Medium

    CVE-2005-0399

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before to 1.7.6, and Thunderbird before 1.0.2, and possibly other applications that use the same library, allows remote attackers to execute arbitrary code via a GIF image with a crafted Netscape extension 2 block and buffer size.

    Published: 23 Mar 2005
    5.1
    Medium

    CVE-2005-0401

    Last Modified: 16 Apr 2026

    FireFox 1.0.1 and Mozilla before 1.7.6 do not sufficiently address all attack vectors for loading chrome files and hijacking drag and drop events, which allows remote attackers to execute arbitrary XUL code by tricking a user into dragging a scrollbar, a variant of CVE-2005-0527, aka "Firescrolling 2."

    Published: 23 Mar 2005
    2.6
    Low

    CVE-2005-0402

    Last Modified: 16 Apr 2026

    Firefox before 1.0.2 allows remote attackers to execute arbitrary code by tricking a user into saving a page as a Firefox sidebar panel, then using the sidebar panel to inject Javascript into a privileged page.

    Published: 23 Mar 2005