CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2005-0825

    Last Modified: 16 Apr 2026

    Buffer overflow in LTris before 1.0.10 allows local users to execute arbitrary code via a crafted highscores file.

    Published: 22 Mar 2005
    5
    Medium

    CVE-2005-0826

    Last Modified: 16 Apr 2026

    OllyDbg 1.10 and earlier allows remote attackers to cause a denial of service (application crash) via a dynamic link library (DLL) with a long filename.

    Published: 22 Mar 2005
    5
    Medium

    CVE-2005-0827

    Last Modified: 16 Apr 2026

    Viewcat.php in (1) RUNCMS 1.1A, (2) Ciamos 0.9.2 RC1, e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allow remote attackers to obtain sensitive information via an invalid parameter to the convertorderbytrans function, which reveals the path in a PHP error message.

    Published: 22 Mar 2005
    5
    Medium

    CVE-2005-0828

    Last Modified: 16 Apr 2026

    highlight.php in (1) RUNCMS 1.1A, (2) CIAMOS 0.9.2 RC1, (3) e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allows remote attackers to read arbitrary PHP files by specifying the pathname in the file parameter, as demonstrated by reading database configuration information from mainfile.php.

    Published: 22 Mar 2005
    7.5
    High

    CVE-2005-0833

    Last Modified: 16 Apr 2026

    Belkin 54G (F5D7130) wireless router allows remote attackers to access restricted resources by sniffing URIs from UPNP datagrams, then accessing those URIs, which do not require authentication.

    Published: 22 Mar 2005
    5
    Medium

    CVE-2005-0834

    Last Modified: 16 Apr 2026

    Belkin 54G (F5D7130) wireless router enables SNMP by default in a manner that allows remote attackers to obtain sensitive information.

    Published: 22 Mar 2005
    5
    Medium

    CVE-2005-0835

    Last Modified: 16 Apr 2026

    The SNMP service in the Belkin 54G (F5D7130) wireless router allows remote attackers to cause a denial of service via unknown vectors.

    Published: 22 Mar 2005
    10
    Critical

    CVE-2005-0836

    Last Modified: 16 Apr 2026

    Argument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06 allows untrusted applications to gain privileges via the value parameter of a property tag in a JNLP file.

    Published: 22 Mar 2005
    5
    Medium

    CVE-2005-0837

    Last Modified: 16 Apr 2026

    IceCast 2.20 allows remote attackers to bypass the XSL parser and obtain the source for XSL files via a request for a .xsl file with a trailing . (dot).

    Published: 22 Mar 2005
    7.5
    High

    CVE-2005-0830

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Xzabite DYNDNSUpdate 0.6.15 and earlier, including the ipcheck function in dyndnsupdate.c, allow remote attackers who spoof a dyndns.org server to execute arbitrary code via unknown vectors.

    Published: 22 Mar 2005
    5
    Medium

    CVE-2005-0831

    Last Modified: 16 Apr 2026

    PHP-Post allows remote attackers to spoof the names of other users by registering with a username containing hex-encoded characters.

    Published: 22 Mar 2005
    4.3
    Medium

    CVE-2005-0832

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in PHP-Post before 0.33 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 22 Mar 2005
    7.5
    High

    CVE-2005-0764

    Last Modified: 16 Apr 2026

    Buffer overflow in command.C for rxvt-unicode before 5.3 allows remote attackers to execute arbitrary code via a crafted file containing long escape sequences.

    Published: 22 Mar 2005
    4.6
    Medium

    CVE-2005-0712

    Last Modified: 16 Apr 2026

    Mac OS X before 10.3.8 users world-writable permissions for certain directories, which may allow local users to gain privileges, possibly via the receipt cache or ColorSync profiles.

    Published: 22 Mar 2005
    4.3
    Medium

    CVE-2005-0829

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in setuser.php of the Digitanium addon to PHP-Fusion 5.01 allows remote attackers to inject arbitrary web script or HTML via the (1) user_name or (2) user_pass parameters.

    Published: 22 Mar 2005
    7.5
    High

    CVE-2005-0838

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the XSL parser for IceCast 2.20 may allow attackers to cause a denial of service and possibly execute arbitrary code via (1) a long test value in an xsl:when tag, (2) a long test value in an xsl:if tag, or (3) a long select value in an xsl:value-of tag.

    Published: 22 Mar 2005
    2.1
    Low

    CVE-2005-0715

    Last Modified: 16 Apr 2026

    AFP Server in Mac OS X before 10.3.8 uses insecure permissions for "Drop Boxes," which allows local users to read the contents of a Drop Box.

    Published: 21 Mar 2005
    4.6
    Medium

    CVE-2005-0713

    Last Modified: 16 Apr 2026

    The Bluetooth Setup Assistant for Mac OS X before 10.3.8 can be launched without a keyboard or Bluetooth device, which allows local users to bypass access restrictions and gain privileges.

    Published: 21 Mar 2005
    7.2
    High

    CVE-2005-0716

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the Core Foundation Library in Mac OS X 10.3.5 and 10.3.6, and possibly earlier versions, allows local users to execute arbitrary code via a long CF_CHARSET_PATH environment variable.

    Published: 21 Mar 2005
    2.1
    Low

    CVE-2005-0400

    Last Modified: 16 Apr 2026

    The ext2_make_empty function call in the Linux kernel before 2.6.11.6 does not properly initialize memory when creating a block for a new directory entry, which allows local users to obtain potentially sensitive information by reading the block.

    Published: 21 Mar 2005
    5
    Medium

    CVE-2005-0796

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/votes" followed by a .. (dot dot) in the vote_filename parameter, which bypasses the check by HolaCMS to ensure that the file is in the holaDB/votes directory.

    Published: 20 Mar 2005
    7.5
    High

    CVE-2005-0800

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in install.php in mcNews 1.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the l parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2005-0720.

    Published: 20 Mar 2005
    5
    Medium

    CVE-2005-0808

    Last Modified: 16 Apr 2026

    Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007.

    Published: 20 Mar 2005
    7.5
    High

    CVE-2005-0809

    Last Modified: 16 Apr 2026

    NotifyLink, when configured for client key retrieval, allows remote attackers to obtain AES keys via a direct request to /hwp/get.asp, then uses a weak encryption scheme (fixed byte reordering) to protect the key, which allows remote attackers to obtain the key via a brute force attack.

    Published: 20 Mar 2005
    4.6
    Medium

    CVE-2005-0811

    Last Modified: 16 Apr 2026

    The web interface in NotifyLink 3.0 does not properly restrict access to functions that have been disabled in the GUI, which allows remote authenticated users to bypass intended restrictions via a direct request to certain URLs.

    Published: 20 Mar 2005
    7.2
    High

    CVE-2005-0816

    Last Modified: 16 Apr 2026

    Buffer overflow in newgrp in Solaris 7 through 9 allows local users to gain root privileges.

    Published: 20 Mar 2005
    4.3
    Medium

    CVE-2005-0818

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in PunBB 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) email or (2) Jabber parameters.

    Published: 20 Mar 2005
    5
    Medium

    CVE-2005-0819

    Last Modified: 16 Apr 2026

    The xvesa code in Novell Netware 6.5 SP2 and SP3 allows remote attackers to redirect the xsession without authentication via a direct request to GUIMirror/Start.

    Published: 20 Mar 2005
    5
    Medium

    CVE-2005-0820

    Last Modified: 16 Apr 2026

    Microsoft Office InfoPath 2003 SP1 includes sensitive information in the Manifest.xsf file in a custom .xsn form, which allows attackers to obtain printer and network information, obtain the database name, username, and password, or obtain the internal web server name.

    Published: 20 Mar 2005
    4.6
    Medium

    CVE-2005-0823

    Last Modified: 16 Apr 2026

    ThePoolClub (1) iPool and (2) iSnooker 1.6.81 and earlier stores usernames and passwords in cleartext in the MyDetails.txt file, which allows local users to gain privileges.

    Published: 20 Mar 2005
    7.5
    High

    CVE-2005-0805

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in Subdreamer Light, when magic_quotes_gpc is enabled, allows remote attackers to execute arbitrary SQL commands via certain parameters that are used as global variables, as demonstrated using the imageid parameter, which is not properly handled by imagegallery.php.

    Published: 20 Mar 2005
    7.5
    High

    CVE-2005-0807

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Cain & Abel before 2.67 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via (1) an IKE packet with a large ID field that is not properly handled by the PSK sniffer filter, (2) the HTTP sniffer filter, or the (3) POP3, (4) SMTP, (5) IMAP, (6) NNTP, or (7) TDS sniffer filters.

    Published: 20 Mar 2005
    5
    Medium

    CVE-2005-0814

    Last Modified: 16 Apr 2026

    Unknown vulnerability in lshd in Lysator LSH 1.x and 2.x before 2.0.1 allows remote attackers to cause a denial of service via unknown vectors.

    Published: 20 Mar 2005
    5
    Medium

    CVE-2005-0817

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the DNSd proxy, as used in Symantec Gateway Security 5400 2.x and 5300 1.x, Enterprise Firewall 7.0.x and 8.x, and VelociRaptor 1100/1200/1300 1.5, allows remote attackers to poison the DNS cache and redirect users to malicious sites.

    Published: 20 Mar 2005
    2.1
    Low

    CVE-2005-0822

    Last Modified: 16 Apr 2026

    Citrix Metaframe Password Manager 2.5 and earlier stores a password in cleartext although it is obfuscated when presented to a user, which allows users to view their secondary passwords even if it is not allowed by policy.

    Published: 20 Mar 2005
    5
    Medium

    CVE-2001-1420

    Last Modified: 16 Apr 2026

    AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application crash) via a long filename, possibly caused by a buffer overflow.

    Published: 20 Mar 2005
    5
    Medium

    CVE-2005-0801

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in includer.cgi in The Includer allows remote attackers to read arbitrary files via (1) a .. (dot dot) or (2) a full pathname in the URL.

    Published: 20 Mar 2005
    4.3
    Medium

    CVE-2005-0802

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.asp in ACS Blog 0.8 through 1.1b allows remote attackers to execute arbitrary web script or HTML via the search parameter.

    Published: 20 Mar 2005
    5
    Medium

    CVE-2005-0803

    Last Modified: 16 Apr 2026

    The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be used, aka "Enhanced Metafile Vulnerability."

    Published: 20 Mar 2005
    5
    Medium

    CVE-2005-0804

    Last Modified: 16 Apr 2026

    Format string vulnerability in MailEnable 1.8 allows remote attackers to cause a denial of service (application crash) via format string specifiers in the mailto field.

    Published: 20 Mar 2005
    5
    Medium

    CVE-2005-0813

    Last Modified: 16 Apr 2026

    Buffer overflow in Initial Redirect (ir) Squid Proxy Plug-In 0.1 and 0.2 may allow attackers to cause a denial of service and execute arbitrary code via unknown vectors.

    Published: 20 Mar 2005
    7.5
    High

    CVE-2005-0775

    Last Modified: 16 Apr 2026

    The reportpost action in misc.php for PhotoPost PHP 5.0 RC3 does not limit the logging data that is sent to the administrator, which allows remote attackers to send large amounts of email to the administrator.

    Published: 20 Mar 2005
    5
    Medium

    CVE-2005-0776

    Last Modified: 16 Apr 2026

    adm-photo.php in PhotoPost PHP 5.0 RC3 does not properly verify administrative privileges before manipulating photos, which could allow remote attackers to manipulate other users' photos.

    Published: 20 Mar 2005
    4.3
    Medium

    CVE-2005-0777

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP 5.0 RC3 allow remote attackers to inject arbitrary web script or HTML via (1) the check_tags function or (2) the editbio field in the user profile.

    Published: 20 Mar 2005
    5
    Medium

    CVE-2005-0778

    Last Modified: 16 Apr 2026

    PhotoPost PHP 5.0 RC3 does not fully verify that an uploaded file is an image file, which allows remote attackers to inject arbitrary Javascript by uploading non-image files with an image extension such as .gif.

    Published: 20 Mar 2005
    5
    Medium

    CVE-2005-0779

    Last Modified: 16 Apr 2026

    PlatinumFTP 1.0.18, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via multiple connection attempts with a \ (backslash) in the username.

    Published: 20 Mar 2005
    7.5
    High

    CVE-2005-0643

    Last Modified: 16 Apr 2026

    Buffer overflow in McAfee Scan Engine 4320 with DAT version before 4357 allows remote attackers to execute arbitrary code via crafted LHA files.

    Published: 20 Mar 2005
    7.5
    High

    CVE-2005-0644

    Last Modified: 16 Apr 2026

    Buffer overflow in McAfee Scan Engine 4320 with DAT version before 4436 allows remote attackers to execute arbitrary code via a malformed LHA file with a type 2 header file name field, a variant of CVE-2005-0643.

    Published: 20 Mar 2005
    7.5
    High

    CVE-2005-0781

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter to pafiledb.php.

    Published: 20 Mar 2005
    4.3
    Medium

    CVE-2005-0782

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the start parameter to pafiledb.php.

    Published: 20 Mar 2005