CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2005-0783

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Phorum before 5.0.14a allows remote attackers to inject arbitrary web script or HTML via the filename of an attached file.

    Published: 20 Mar 2005
    4.3
    Medium

    CVE-2005-0785

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in usersrecentposts in YaBB 2.0 rc1 allows remote attackers to inject arbitrary web script or HTML via the username parameter.

    Published: 20 Mar 2005
    2.1
    Low

    CVE-2005-0787

    Last Modified: 16 Apr 2026

    Wine 20050211 and earlier creates temp files with world readable permissions and predictable file names, which allows local users to obtain sensitive information, such as passwords.

    Published: 20 Mar 2005
    7.5
    High

    CVE-2005-0810

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in NotifyLink before 3.0 allows remote attackers to execute arbitrary SQL commands via the URL.

    Published: 20 Mar 2005
    5
    Medium

    CVE-2005-0812

    Last Modified: 16 Apr 2026

    The web interface in NotifyLink 3.0 displays passwords in cleartext on the administrative page, which could allow remote attackers or local users to obtain sensitive information.

    Published: 20 Mar 2005
    7.5
    High

    CVE-2005-0821

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Citrix MetaFrame Conferencing Manager 3.0 allows conference members to bypass organizer restrictions to control the keyboard and mouse.

    Published: 20 Mar 2005
    5
    Medium

    CVE-2005-0806

    Last Modified: 16 Apr 2026

    Evolution 2.0.3 allows remote attackers to cause a denial of service (application crash or hang) via crafted messages, possibly involving charsets in attachment filenames.

    Published: 20 Mar 2005
    2.1
    Low

    CVE-2005-1041

    Last Modified: 16 Apr 2026

    The fib_seq_start function in fib_hash.c in Linux kernel allows local users to cause a denial of service (system crash) via /proc/net/route.

    Published: 19 Mar 2005
    2.1
    Low

    CVE-2005-0515

    Last Modified: 16 Apr 2026

    Smc.exe in My Firewall Plus 5.0 build 1117, and possibly other versions, does not drop privileges before launching the Log Viewer export functionality, which allows local users to corrupt arbitrary files by saving log files.

    Published: 18 Mar 2005
    10
    Critical

    CVE-2005-0768

    Last Modified: 16 Apr 2026

    Buffer overflow in the administration web server for GoodTech Telnet Server 4.0 and 5.0, and possibly all versions before 5.0.7, allows remote attackers to execute arbitrary code via a long string to port 2380.

    Published: 18 Mar 2005
    7.5
    High

    CVE-2005-0769

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in OpenSLP before 1.1.5 allow remote attackers to have an unknown impact via malformed SLP packets.

    Published: 18 Mar 2005
    7.5
    High

    CVE-2005-0770

    Last Modified: 16 Apr 2026

    Format string vulnerability in DataRescue Interactive Disassembler and Debugger (IDA) Pro 4.7.0.830 allows remote attackers or local users to cause a denial of service (CPU consumption or application crash) and possibly execute arbitrary code via format string specifiers in a dynamic link library (DLL) name.

    Published: 18 Mar 2005
    7.2
    High

    CVE-2005-0749

    Last Modified: 16 Apr 2026

    The load_elf_library in the Linux kernel before 2.6.11.6 allows local users to cause a denial of service (kernel crash) via a crafted ELF library or executable, which causes a free of an invalid pointer.

    Published: 18 Mar 2005
    7.2
    High

    CVE-2005-0385

    Last Modified: 16 Apr 2026

    Buffer overflow in luxman before 0.41, if used with certain insecure svgalib libraries, allows local users to execute arbitrary code via a long -f command line argument.

    Published: 17 Mar 2005
    5
    Medium

    CVE-2005-0083

    Last Modified: 16 Apr 2026

    MySQL MaxDB 7.5.00 for Windows, and possibly earlier versions and other platforms, allows remote attackers to cause a denial of service (application crash) via invalid parameters to the (1) DBMCli_String::ReallocString, (2) DBMCli_String::operator, (3) DBMCli_Buffer::ForceResize, (4) DBMCli_Wizard::InstallDatabase, (5) DBMCli_Devspaces::Complete, (6) DBMWeb_TemplateWizard::askForWriteCountStep5, or (7) DBMWeb_DBMWeb::wizardDB functions, which triggers a null dereference.

    Published: 17 Mar 2005
    6.4
    Medium

    CVE-2005-0815

    Last Modified: 16 Apr 2026

    Multiple "range checking flaws" in the ISO9660 filesystem handler in Linux 2.6.11 and earlier may allow attackers to cause a denial of service or corrupt memory via a crafted filesystem.

    Published: 17 Mar 2005
    7.2
    High

    CVE-2005-0352

    Last Modified: 16 Apr 2026

    Servers Alive 4.1 and 5.0, when running as a service, does not drop SYSTEM privileges before loading local manual under the help menu, which allows local users to gain privileges.

    Published: 16 Mar 2005
    2.1
    Low

    CVE-2005-0396

    Last Modified: 16 Apr 2026

    Desktop Communication Protocol (DCOP) daemon, aka dcopserver, in KDE before 3.4 allows local users to cause a denial of service (dcopserver consumption) by "stalling the DCOP authentication process."

    Published: 16 Mar 2005
    6.4
    Medium

    CVE-2005-0794

    Last Modified: 16 Apr 2026

    ZPanel 2.0 and 2.5 beta 10 does not remove or protect installation scripts after they have been used, which allows remote attackers to reinstall the software and possibly cause a denial of service via a direct request to install.php.

    Published: 15 Mar 2005
    5
    Medium

    CVE-2005-0797

    Last Modified: 16 Apr 2026

    Novell iChain Mini FTP Server 2.3 displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks.

    Published: 15 Mar 2005
    7.5
    High

    CVE-2005-0798

    Last Modified: 16 Apr 2026

    Novell iChain Mini FTP Server 2.3, and possibly earlier versions, does not limit the number of incorrect logins, which makes it easier for remote attackers to conduct brute force login attacks.

    Published: 15 Mar 2005
    5
    Medium

    CVE-2005-0799

    Last Modified: 16 Apr 2026

    MySQL 4.1.9, and possibly earlier versions, allows remote attackers with certain privileges to cause a denial of service (application crash) via a use command followed by an MS-DOS device name such as (1) LPT1 or (2) PRN.

    Published: 15 Mar 2005
    7.5
    High

    CVE-2005-0793

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in zpanel.php in ZPanel allows remote attackers to (1) execute arbitrary PHP code in ZPanel 2.0 or (2) include local files in ZPanel 2.5 beta 10 and earlier by modifying the page parameter.

    Published: 15 Mar 2005
    7.5
    High

    CVE-2005-0792

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in ZPanel 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter to index.php or (2) page parameter to zpanel.php.

    Published: 15 Mar 2005
    5
    Medium

    CVE-2005-0384

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the PPP driver for the Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via a pppd client.

    Published: 15 Mar 2005
    4.3
    Medium

    CVE-2005-0791

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in adframe.php in phpAdsNew 2.0.4-pr1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the refresh parameter.

    Published: 14 Mar 2005
    5
    Medium

    CVE-2005-0795

    Last Modified: 16 Apr 2026

    HolaCMS 1.4.9 does not restrict file access to the holaDB/votes directory, which allows remote attackers to overwrite arbitrary files via a modified vote_filename parameter.

    Published: 14 Mar 2005
    5
    Medium

    CVE-2005-0789

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in LimeWire 3.9.6 through 4.6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in a magnet request.

    Published: 14 Mar 2005
    5
    Medium

    CVE-2005-0790

    Last Modified: 16 Apr 2026

    phpAdsNew 2.0.4 allows remote attackers to obtain sensitive information via a direct request to (1) lib-xmlrpcs.inc.php, (2) maintenance-activation.php, (3) maintenance-cleantables.php, (4) maintenance-autotargeting.php, (5) maintenance-reports.php, (6) phpads.php, (7) remotehtmlview.php, (8) click.php, (9) adcontent.php, which reveal the path in a PHP error message.

    Published: 14 Mar 2005
    7.5
    High

    CVE-2005-0786

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in gb_new.inc in SimpGB allows remote attackers to execute arbitrary SQL commands via the quote parameter to guestbook.php.

    Published: 14 Mar 2005
    5
    Medium

    CVE-2005-0788

    Last Modified: 16 Apr 2026

    LimeWire 4.1.2 through 4.5.6 allows remote attackers to read arbitrary files by specifying the full pathname in a Gnutella GET request.

    Published: 14 Mar 2005
    2.6
    Low

    CVE-2005-3110

    Last Modified: 16 Apr 2026

    Race condition in ebtables netfilter module (ebtables.c) in Linux 2.6, when running on an SMP system that is operating under a heavy load, might allow remote attackers to cause a denial of service (crash) via a series of packets that cause a value to be modified after it has been read but before it has been locked.

    Published: 14 Mar 2005
    5
    Medium

    CVE-2005-0733

    Last Modified: 16 Apr 2026

    PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to determine the existence of files via an HTTP request with a full pathname, which produces different messages whether the file exists or not.

    Published: 13 Mar 2005
    7.5
    High

    CVE-2005-0737

    Last Modified: 16 Apr 2026

    Buffer overflow in Yahoo! Messenger allows remote attackers to execute arbitrary code via the offline mode.

    Published: 13 Mar 2005
    7.5
    High

    CVE-2005-0743

    Last Modified: 16 Apr 2026

    The custom avatar uploading feature (uploader.php) for XOOPS 2.0.9.2 and earlier allows remote attackers to upload arbitrary PHP scripts, whose file extensions are not filtered.

    Published: 13 Mar 2005
    10
    Critical

    CVE-2005-0744

    Last Modified: 16 Apr 2026

    The web GUI for Novell iChain 2.2 and 2.3 SP2 and SP3 allows attackers to hijack sessions and gain administrator privileges by (1) sniffing the connection on TCP port 51100 and replaying the authentication information or (2) obtaining and replaying the PCZQX02 authentication cookie from the browser.

    Published: 13 Mar 2005
    5
    Medium

    CVE-2005-0732

    Last Modified: 16 Apr 2026

    PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to obtain the full path of the web server via a request for a non-existent filename, which leaks the full path in an error message.

    Published: 13 Mar 2005
    4.3
    Medium

    CVE-2005-0742

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Sun Java System Application Server 7 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 13 Mar 2005
    7.5
    High

    CVE-2005-0729

    Last Modified: 16 Apr 2026

    Format string vulnerability in Xpand Rally 1.1.0.0 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a message.

    Published: 13 Mar 2005
    5
    Medium

    CVE-2005-0730

    Last Modified: 16 Apr 2026

    PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service via a request to a file on the floppy drive, as demonstrated using A:\a.txt.

    Published: 13 Mar 2005
    5
    Medium

    CVE-2005-0734

    Last Modified: 16 Apr 2026

    PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service (memory exhaustion and process crash) via a large number of HTTP requests.

    Published: 13 Mar 2005
    10
    Critical

    CVE-2005-0735

    Last Modified: 16 Apr 2026

    newsscript.pl for NewsScript allows remote attackers to gain privileges by setting the mode parameter to admin.

    Published: 13 Mar 2005
    5
    Medium

    CVE-2005-0738

    Last Modified: 16 Apr 2026

    Stack consumption vulnerability in Microsoft Exchange Server 2003 SP1 allows users to cause a denial of service (hang) by deleting or moving a folder with deeply nested subfolders, which causes Microsoft Exchange Information Store service (Store.exe) to hang as a result of a large number of recursive calls.

    Published: 13 Mar 2005
    5
    Medium

    CVE-2005-0746

    Last Modified: 16 Apr 2026

    The Mini FTP server in Novell iChain 2.2 and 2.3 SP2 and earlier allows remote unauthenticated attackers to obtain the full path of the server via the PWD command.

    Published: 13 Mar 2005
    5
    Medium

    CVE-2005-0780

    Last Modified: 16 Apr 2026

    paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) auth.php, (2) login.php, (3) category.php, (4) file.php, (5) team.php, (6) license.php, (7) custom.php, (8) admins.php, or (9) backupdb.php, which reveal the path in a PHP error message.

    Published: 12 Mar 2005
    Unknown

    CVE-2005-0714

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-0340. Reason: This candidate is a reservation duplicate of CVE-2005-0340. Notes: All CVE users should reference CVE-2005-0340 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 12 Mar 2005
    7.5
    High

    CVE-2005-0721

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in modules.php in eXPerience2 allows remote attackers to execute arbitrary PHP code by modifying the file parameter to reference a URL on a remote web server that contains the code.

    Published: 12 Mar 2005
    5
    Medium

    CVE-2005-0724

    Last Modified: 16 Apr 2026

    paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via (1) an invalid str parameter to pafiledb.php, or a direct request to (2) viewall.php, (3) stats.php, (4) search.php, (5) rate.php, (6) main.php, (7) license.php, (8) category.php, (9) download.php, (10) file.php, (11) email.php, or (12) admin.php, which reveals the path in a PHP error message.

    Published: 12 Mar 2005
    Unknown

    CVE-2005-0727

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-0735. Reason: This candidate is a duplicate of CVE-2005-0735. Notes: All CVE users should reference CVE-2005-0727 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 12 Mar 2005
    Unknown

    CVE-2005-0728

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-0736. Reason: This candidate is a duplicate of CVE-2005-0736. Notes: All CVE users should reference CVE-2005-0736 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 12 Mar 2005