CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2005-0726

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in editpost.php in UBB.threads 6.0 allows remote attackers to execute arbitrary SQL commands via the Number parameter.

    Published: 12 Mar 2005
    2.1
    Low

    CVE-2005-0711

    Last Modified: 16 Apr 2026

    MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allows local users with CREATE TEMPORARY TABLE privileges to overwrite arbitrary files via a symlink attack.

    Published: 11 Mar 2005
    5
    Medium

    CVE-2005-0766

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the sFlow dissector in Ethereal 0.9.14 through 0.10.9 allows remote attackers to cause a denial of service (application crash).

    Published: 11 Mar 2005
    2.1
    Low

    CVE-2005-0135

    Last Modified: 16 Apr 2026

    The unw_unwind_to_user function in unwind.c on Itanium (ia64) architectures in Linux kernel 2.6 allows local users to cause a denial of service (system crash).

    Published: 11 Mar 2005
    2.1
    Low

    CVE-2005-0136

    Last Modified: 16 Apr 2026

    The Linux kernel before 2.6.11 on the Itanium IA64 platform has certain "ptrace corner cases" that allow local users to cause a denial of service (crash) via crafted syscalls, possibly related to MCA/INIT, a different vulnerability than CVE-2005-1761.

    Published: 11 Mar 2005
    2.1
    Low

    CVE-2005-0137

    Last Modified: 16 Apr 2026

    Linux kernel 2.6 on Itanium (ia64) architectures allows local users to cause a denial of service via a "missing Itanium syscall table entry."

    Published: 11 Mar 2005
    5
    Medium

    CVE-2005-0739

    Last Modified: 16 Apr 2026

    The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the dissect_pdus and pduval_to_str functions.

    Published: 11 Mar 2005
    5
    Medium

    CVE-2005-0765

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the JXTA dissector in Ethereal 0.10.9 allows remote attackers to cause a denial of service (application crash).

    Published: 11 Mar 2005
    7.5
    High

    CVE-2005-0704

    Last Modified: 16 Apr 2026

    Buffer overflow in the Etheric dissector in Ethereal 0.10.7 through 0.10.9 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code.

    Published: 11 Mar 2005
    5
    Medium

    CVE-2005-0705

    Last Modified: 16 Apr 2026

    The GPRS-LLC dissector in Ethereal 0.10.7 through 0.10.9, with the "ignore cipher bit" option enabled. allows remote attackers to cause a denial of service (application crash).

    Published: 11 Mar 2005
    4.6
    Medium

    CVE-2005-0709

    Last Modified: 16 Apr 2026

    MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access libc calls, as demonstrated by using strcat, on_exit, and exit.

    Published: 11 Mar 2005
    4.6
    Medium

    CVE-2005-0710

    Last Modified: 16 Apr 2026

    MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to bypass library path restrictions and execute arbitrary libraries by using INSERT INTO to modify the mysql.func table, which is processed by the udf_init function.

    Published: 11 Mar 2005
    7.5
    High

    CVE-2005-0774

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in member.php and possibly other scripts in PhotoPost PHP 5.0 RC3 allows remote attackers to execute arbitrary SQL commands via the uid parameter.

    Published: 10 Mar 2005
    7.2
    High

    CVE-2005-0707

    Last Modified: 16 Apr 2026

    Buffer overflow in the IMAP daemon (IMAP4d32.exe) for Ipswitch Collaboration Suite (ICS) before 8.15 Hotfix 1 allows remote authenticated users to execute arbitrary code via a long EXAMINE command.

    Published: 10 Mar 2005
    5
    Medium

    CVE-2005-0731

    Last Modified: 16 Apr 2026

    PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to Filelist.html.

    Published: 10 Mar 2005
    7.5
    High

    CVE-2005-0748

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in initdb.php for WEBInsta Mailing list manager 1.3d allows remote attackers to execute arbitrary PHP code by modifying the absolute_path parameter to reference a URL on a remote web server that contains the code.

    Published: 10 Mar 2005
    4.6
    Medium

    CVE-2005-0745

    Last Modified: 16 Apr 2026

    UTStarcom iAN-02EX VoIP Analog Terminal Adaptor (ATA) allows local users to bypass ATA access restrictions by dialing "*#26845#" and causing a device reset.

    Published: 9 Mar 2005
    4.3
    Medium

    CVE-2005-0549

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the "View Log Files" function.

    Published: 9 Mar 2005
    2.1
    Low

    CVE-2005-0719

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the systems message queue in HP Tru64 Unix 4.0F PK8 through 5.1B-2/PK4 allows local users to cause a denial of service (process crash) for processes such as nfsstat, pfstat, arp, ogated, rarpd, route, sendmail, srconfig, strsetup, trpt, netstat, and xntpd.

    Published: 9 Mar 2005
    2.1
    Low

    CVE-2005-0736

    Last Modified: 16 Apr 2026

    Integer overflow in sys_epoll_wait in eventpoll.c for Linux kernel 2.6 to 2.6.11 allows local users to overwrite kernel memory via a large number of events.

    Published: 9 Mar 2005
    5
    Medium

    CVE-2005-0398

    Last Modified: 16 Apr 2026

    The KAME racoon daemon in ipsec-tools before 0.5 allows remote attackers to cause a denial of service (crash) via malformed ISAKMP packets.

    Published: 9 Mar 2005
    1.2
    Low

    CVE-2005-0448

    Last Modified: 16 Apr 2026

    Race condition in the rmtree function in File::Path.pm in Perl before 5.8.4 allows local users to create arbitrary setuid binaries in the tree being deleted, a different vulnerability than CVE-2004-0452.

    Published: 9 Mar 2005
    7.5
    High

    CVE-2005-0706

    Last Modified: 16 Apr 2026

    Buffer overflow in discdb.c for grip 3.1.2 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing the cddb lookup to return more matches than expected.

    Published: 9 Mar 2005
    2.1
    Low

    CVE-2005-0099

    Last Modified: 16 Apr 2026

    The SDL port of abuse (abuse-SDL) before 2.00 does not properly drop privileges before creating certain files, which allows local users to create or overwrite arbitrary files.

    Published: 8 Mar 2005
    7.5
    High

    CVE-2005-0699

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the dissect_a11_radius function in the CDMA A11 (3G-A11) dissector (packet-3g-a11.c) for Ethereal 0.10.9 and earlier allow remote attackers to execute arbitrary code via RADIUS authentication packets with large length values.

    Published: 8 Mar 2005
    7.5
    High

    CVE-2005-0685

    Last Modified: 16 Apr 2026

    Multiple access validation errors in OutStart Participate Enterprise (PE) allow remote attackers to (1) browse arbitrary directory trees by modifying the rootFolder parameter to displaynavigator.jsp, (2) rename arbitrary directory objects by modifying the selectedObject parameter to renamepopup.jsp, (3) delete arbitrary directory objects by modifying the selectedObjectsCSV parameter to displaydeletenavigator.jsp, and conduct other unauthorized activities via the (4) showDeleteView, (5) showWebFolderView, (6) showLibraryView, (7) showMyLibraryView, (8) singleSelectObject, (9) processRadioSelection, (10) processCheckboxSelection, (11) singleSelectObject, (12) addToSelectedObjects, or (13) removeFromSelectedObjects commands.

    Published: 8 Mar 2005
    7.5
    High

    CVE-2005-0696

    Last Modified: 16 Apr 2026

    Buffer overflow in ArGoSoft FTP Server 1.4.2.8 allows remote authenticated users to execute arbitrary code via a long DELE command. NOTE: this issue was later reported to also affect 1.4.3.5.

    Published: 8 Mar 2005
    4.3
    Medium

    CVE-2005-0723

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the jumpmenu function in functions.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL parameters, which is not properly cleansed in the $pageurl variable, as demonstrated using pafiledb.php.

    Published: 8 Mar 2005
    10
    Critical

    CVE-2005-0353

    Last Modified: 16 Apr 2026

    Buffer overflow in the Sentinel LM (Lservnt) service in the Sentinel License Manager 7.2.0.2 allows remote attackers to execute arbitrary code by sending a large amount of data to UDP port 5093.

    Published: 8 Mar 2005
    4.6
    Medium

    CVE-2005-0098

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the SDL port of abuse (abuse-SDL) before 2.00 allow local users to execute arbitrary code via the command line.

    Published: 8 Mar 2005
    7.5
    High

    CVE-2005-0720

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in admin/header.php in PHP mcNews 1.3 allows remote attackers to execute arbitrary PHP code by modifying the skinfile parameter to reference a URL on a remote web server that contains the code.

    Published: 8 Mar 2005
    7.5
    High

    CVE-2005-0725

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the getAllbyArticle function in wfsfiles.php for WF-Sections (wfsections) 1.07 allows remote attackers to execute arbitrary SQL commands via the articleid parameter to article.php.

    Published: 8 Mar 2005
    4.3
    Medium

    CVE-2005-0741

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a usersrecentposts action.

    Published: 8 Mar 2005
    5
    Medium

    CVE-2005-0747

    Last Modified: 16 Apr 2026

    ApplyYourself i-Class allows remote attackers to obtain sensitive information about their own applications by reusing the hidden ID field, as demonstrated using the id parameter to ApplicantDecision.asp.

    Published: 8 Mar 2005
    7.2
    High

    CVE-2005-0403

    Last Modified: 16 Apr 2026

    init_dev in tty_io.c in the Red Hat backport of NPTL to Red Hat Enterprise Linux 3 does not properly clear controlling tty's in multi-threaded applications, which allows local users to cause a denial of service (crash) and possibly gain tty access via unknown attack vectors that trigger an access of a pointer to a freed structure.

    Published: 8 Mar 2005
    7.5
    High

    CVE-2005-0663

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php for MercuryBoard 1.1.2 allows remote attackers to inject arbitrary SQL commands via the f parameter.

    Published: 7 Mar 2005
    7.5
    High

    CVE-2005-0680

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in download_center_lite.inc.php for Download Center Lite 1.6 allows remote attackers to execute arbitrary PHP code by modifying the script_root parameter to reference a URL on a remote web server that contains the code.

    Published: 7 Mar 2005
    5
    Medium

    CVE-2005-0722

    Last Modified: 16 Apr 2026

    eXPerience2 allows remote attackers to obtain the full path for the web root via a direct request to modules.php without any parameters, which leaks the path in a PHP error message.

    Published: 7 Mar 2005
    7.5
    High

    CVE-2005-0669

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in mod.php for phpCOIN 1.2.0 through 1.2.1b allow remote attackers to execute arbitrary SQL commands via the (1) the faq_id in the faq mod, (2) the id parameter in the pages mod, (3) the id parameter in the siteinfo module, (4) the topic_id parameter in the articles module, (5) the ord_id in the orders module, (6) the dom_id parameter in the domains module, or (7) the invd_id parameter in the invoices module.

    Published: 7 Mar 2005
    7.5
    High

    CVE-2005-0672

    Last Modified: 16 Apr 2026

    Carsten's 3D Engine (Ca3DE), March 2004 version and earlier, allows remote attackers to execute arbitrary code via text strings that are not null terminated, which triggers a null dereference.

    Published: 7 Mar 2005
    4.3
    Medium

    CVE-2005-0673

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in usercp_register.php for phpBB 2.0.13 allows remote attackers to inject arbitrary web script or HTML by setting the (1) allowhtml, (2) allowbbcode, or (3) allowsmilies parameters to inject HTML into signatures for personal messages, possibly when they are processed by privmsg.php or viewtopic.php.

    Published: 7 Mar 2005
    7.5
    High

    CVE-2005-0689

    Last Modified: 16 Apr 2026

    includer.cgi in The Includer allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the URL or (2) the template parameter.

    Published: 7 Mar 2005
    2.1
    Low

    CVE-2005-0690

    Last Modified: 16 Apr 2026

    Gene6 FTP Server does not properly restrict access to the control console, which allows local users to modify the server configuration and gain privileges, as demonstrated by defining a SITE command.

    Published: 7 Mar 2005
    7.5
    High

    CVE-2005-0697

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the process_picture function xp_publish.php in CopperExport 0.2.1 allows remote attackers to execute arbitrary SQL commands, possibly via the (1) title, (2) caption, or (3) keywords parameters.

    Published: 7 Mar 2005
    5
    Medium

    CVE-2005-0703

    Last Modified: 16 Apr 2026

    Xerox MicroServer Web Server for various WorkCentre products including M35/M45/M55 2.028.11.000 through 2.97.20.032 and 4.84.16.000 through 4.97.20.032, Pro 35/45/55 3.028.11.000 through 3.97.20.032, Pro 65/75/90 1.001.00.060 through 1.001.02.084, and others, has an "unauthenticated account," which allows remote attackers to modify system configuration, a different vulnerability than CVE-2005-1179.

    Published: 7 Mar 2005
    5
    Medium

    CVE-2005-0702

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in phpMyFAQ 1.4 and 1.5 allows remote attackers to add FAQ records to the database via the username field in forum messages.

    Published: 7 Mar 2005
    5
    Medium

    CVE-2005-0701

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Oracle Database Server 8i and 9i allows remote attackers to read or rename arbitrary files via "\\.\\.." (modified dot dot backslash) sequences to UTL_FILE functions such as (1) UTL_FILE.FOPEN or (2) UTL_FILE.frename.

    Published: 7 Mar 2005
    2.1
    Low

    CVE-2005-0652

    Last Modified: 16 Apr 2026

    Unknown vulnerability in HP OpenVMS VAX 7.x and 6.x and OpenVMS Alpha 7.x or 6.x allows local users to access privileged files.

    Published: 7 Mar 2005
    4.3
    Medium

    CVE-2005-0548

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search function.

    Published: 7 Mar 2005
    5
    Medium

    CVE-2005-0655

    Last Modified: 16 Apr 2026

    auraCMS 1.5 allows remote attackers to obtain sensitive information via an HTTP request with an invalid id parameter to (1) teman.php, (2) hal.php, or (3) arsip.php, which reveals the path in a PHP error message.

    Published: 7 Mar 2005