CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2005-0656

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in auraCMS 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) hits parameter to hits.php, (2) query parameter to index.php, or (3) theCount parameter to counter.php.

    Published: 7 Mar 2005
    6.4
    Medium

    CVE-2005-0657

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Computalynx CProxy 3.3.x and 3.4.x through 3.4.4 allows remote attackers to read arbitrary files or cause a denial of service (application crash) via a .. (dot dot) in an HTTP request.

    Published: 7 Mar 2005
    7.5
    High

    CVE-2005-0658

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in a third party extension to TYPO3 allows remote attackers to execute arbitrary SQL commands via the category_uid parameter.

    Published: 7 Mar 2005
    5
    Medium

    CVE-2005-0659

    Last Modified: 16 Apr 2026

    phpBB 2.0.13 and earlier allows remote attackers to obtain sensitive information via a direct request to oracle.php, which reveals the path in a PHP error message.

    Published: 7 Mar 2005
    4.3
    Medium

    CVE-2005-0660

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in D-Forum 1.11 allows remote attackers to inject arbitrary web script or HTML via certain fields, as demonstrated using the page parameter in nav.php3.

    Published: 7 Mar 2005
    7.5
    High

    CVE-2005-0661

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the getwbbuserdata function in session.php for Woltlab Burning Board 2.0.3 through 2.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) userid or (2) lastvisit cookie.

    Published: 7 Mar 2005
    5
    Medium

    CVE-2005-0654

    Last Modified: 16 Apr 2026

    gifload.exe in GIMP 2.0.5, 2.2.3, and possibly 2.2.4 allows remote attackers or local users to cause a denial of service (application crash) via the image descriptor (1) height or (2) width fields set to zero.

    Published: 7 Mar 2005
    5.1
    Medium

    CVE-2005-0665

    Last Modified: 16 Apr 2026

    Format string vulnerability in xv before 3.10a allows remote attackers to execute arbitrary code via format string specifiers in a filename.

    Published: 7 Mar 2005
    4.6
    Medium

    CVE-2005-0666

    Last Modified: 16 Apr 2026

    Unknown vulnerability in PaX from the September 2003 release to 2.2 before 2005.03.05, related to SEGMEXEC or RANDEXEC and VMA mirroring, allows local users and possibly remote attackers to bypass intended access restrictions and execute arbitrary code.

    Published: 7 Mar 2005
    4.3
    Medium

    CVE-2005-0675

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.5 allows remote attackers to inject arbitrary web script or HTML via the (1) list or (2) frommethod parameters.

    Published: 7 Mar 2005
    7.5
    High

    CVE-2005-0676

    Last Modified: 16 Apr 2026

    index.php in Zorum 3.5 allows remote attackers to trigger an SQL error, and possibly inject arbitrary SQL commands, via the search capability.

    Published: 7 Mar 2005
    5
    Medium

    CVE-2005-0677

    Last Modified: 16 Apr 2026

    index.php for Zorum 3.5 allows remote attackers to perform certain actions as other users by modifying the id parameter.

    Published: 7 Mar 2005
    7.5
    High

    CVE-2005-0678

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in formmail.inc.php for Form Mail Script 2.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the script_root to reference a URL on a remote web server that contains the code.

    Published: 7 Mar 2005
    4.3
    Medium

    CVE-2005-0682

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in common.inc in Drupal before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via certain inputs.

    Published: 7 Mar 2005
    7.5
    High

    CVE-2005-0686

    Last Modified: 16 Apr 2026

    Integer overflow in mlterm 2.5.0 through 2.9.1, with gdk-pixbuf support enabled, allows remote attackers to execute arbitrary code via a large image file that is used as a background.

    Published: 7 Mar 2005
    Unknown

    CVE-2005-0683

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-0659. Reason: This candidate is a duplicate of CVE-2005-0659. Notes: All CVE users should reference CVE-2005-0659 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 Mar 2005
    7.5
    High

    CVE-2005-0693

    Last Modified: 16 Apr 2026

    Buffer overflow in JoWood Chaser 1.50 and earlier allows remote attackers to cause a denial of service (client or server crash) and execute arbitrary code via a long nickname.

    Published: 7 Mar 2005
    5
    Medium

    CVE-2005-0694

    Last Modified: 16 Apr 2026

    Hosting Controller 6.1 Hotfix 1.7 and earlier stores log files under the web root, which allows remote attackers to obtain sensitive information via a direct request to HCDiskQuotaService.csv.

    Published: 7 Mar 2005
    4.6
    Medium

    CVE-2005-0698

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in PHPWebLog 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) G_PATH parameter to init.inc.php or the (2) PATH parameter to index.php to reference a URL on a remote web server that contains the code.

    Published: 7 Mar 2005
    4.6
    Medium

    CVE-2005-0653

    Last Modified: 16 Apr 2026

    phpMyAdmin 2.6.1 does not properly grant permissions on tables with an underscore in the name, which grants remote authenticated users more privileges than intended.

    Published: 7 Mar 2005
    4.3
    Medium

    CVE-2005-0662

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php for MercuryBoard 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the Avatar field.

    Published: 7 Mar 2005
    4.3
    Medium

    CVE-2005-0670

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpCOIN 1.2.0 through 1.2.1b allows remote attackers to inject arbitrary web script or HTML via (1) the new parameter to mod.php, (2) the w parameter to mod.php, (3) the e parameter to login.php, (4) the o parameter to login.php, and possibly other scripts.

    Published: 7 Mar 2005
    7.5
    High

    CVE-2005-0679

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in tell_a_friend.inc.php for Tell A Friend Script 2.7 before 20050305 allows remote attackers to execute arbitrary PHP code by modifying the script_root parameter to reference a URL on a remote web server that contains the code. NOTE: it was later reported that 2.4 is also affected.

    Published: 7 Mar 2005
    5
    Medium

    CVE-2005-0695

    Last Modified: 16 Apr 2026

    The password recovery feature (forgotpassword.asp) in Hosting Controller 6.1 Hotfix 1.7 and earlier allows remote attackers to determine the owner's e-mail address by providing a portion of the domain name to the "login ID" field.

    Published: 7 Mar 2005
    5
    Medium

    CVE-2005-0700

    Last Modified: 16 Apr 2026

    The export_index action in myadmin.php for Aztek Forum 4.0 allows remote attackers to obtain database files, possibly by setting the ATK_ADMIN cookie.

    Published: 7 Mar 2005
    5.1
    Medium

    CVE-2005-0667

    Last Modified: 16 Apr 2026

    Buffer overflow in Sylpheed before 1.0.3 and other versions before 1.9.5 allows remote attackers to execute arbitrary code via an e-mail message with certain headers containing non-ASCII characters that are not properly handled when the user replies to the message.

    Published: 7 Mar 2005
    7.2
    High

    CVE-2005-3629

    Last Modified: 16 Apr 2026

    initscripts in Red Hat Enterprise Linux 4 does not properly handle certain environment variables when /sbin/service is executed, which allows local users with sudo permissions for /sbin/service to gain root privileges via unknown vectors.

    Published: 7 Mar 2005
    5
    Medium

    CVE-2005-0681

    Last Modified: 16 Apr 2026

    Nokia Symbian 60 allows remote attackers to cause a denial of service (phone restart) via a Bluetooth nickname.

    Published: 6 Mar 2005
    7.5
    High

    CVE-2005-0691

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in article mode for modules.php in SocialMPN allows remote attackers to execute arbitrary PHP code by modifying the name parameter to reference a URL on a remote web server that contains the code.

    Published: 6 Mar 2005
    4.3
    Medium

    CVE-2005-0692

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in fusion_core.php for PHP-Fusion 5.x allows remote attackers to inject arbitrary web script or HTML via a message with IMG bbcode containing character-encoded Javascript.

    Published: 6 Mar 2005
    7.5
    High

    CVE-2005-0687

    Last Modified: 16 Apr 2026

    Format string vulnerability in Hashcash 1.16 allows remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via format string specifiers in a reply address, which is not properly handled when printing the header.

    Published: 6 Mar 2005
    5.6
    Medium

    CVE-2005-0109

    Last Modified: 16 Apr 2026

    Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.

    Published: 5 Mar 2005
    5
    Medium

    CVE-2005-0688

    Last Modified: 16 Apr 2026

    Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, aka a reoccurrence of the "Land" vulnerability (CVE-1999-0016).

    Published: 5 Mar 2005
    4.6
    Medium

    CVE-2005-0627

    Last Modified: 16 Apr 2026

    Qt before 3.3.4 searches the BUILD_PREFIX directory, which could be world-writable, to load shared libraries regardless of the LD_LIBRARY_PATH environment variable, which allows local users to execute arbitrary programs.

    Published: 4 Mar 2005
    5
    Medium

    CVE-2005-0637

    Last Modified: 16 Apr 2026

    The copy functions in locore.s such as copyout in OpenBSD 3.5 and 3.6, and possibly other BSD based operating systems, may allow attackers to exceed certain address boundaries and modify kernel memory.

    Published: 4 Mar 2005
    4.3
    Medium

    CVE-2005-0645

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in show.inc.php in cuteNews 1.3.6 allows remote attackers to inject arbitrary HTML, web script, and PHP code via the (1) CLIENT-IP or (2) X-FORWARDED-FOR header in an HTTP POST request to show_news.php.

    Published: 4 Mar 2005
    5
    Medium

    CVE-2005-0647

    Last Modified: 16 Apr 2026

    admin_setup.php in paNews 2.0.4b allows remote attackers to inject arbitrary PHP code via the (1) $form[comments] or (2) $form[autoapprove] parameters, which are written to config.php.

    Published: 4 Mar 2005
    4.3
    Medium

    CVE-2005-0650

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ProjectBB 0.4.5.1 allow remote attackers to inject arbitrary web script or HTML via (1) the pages parameter to divers.php (incorrectly referred to as "drivers.php" by some sources), (2) in the search feature text area, (3) forum name, (4) site name or (5) the maximum avatar size in the option section, (5) new category or (6) new forum fields in the forum section.

    Published: 4 Mar 2005
    7.5
    High

    CVE-2005-0651

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in ProjectBB 0.4.5.1 allow remote attackers to execute arbitrary SQL commands via (1) liste or (2) desc parameters to divers.php (incorrectly referred to as "drivers.php" by some sources), (3) the search feature text area, (4) post name in the post creation feature, (5) City, (6) Homepage, (7) ICQ, (8) AOL, (9) Yahoo!, (10) MSN, or (11) e-mail fields in the profile feature or (12) the new field in the moderator section.

    Published: 4 Mar 2005
    7.5
    High

    CVE-2005-0642

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the Query Designer for Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 allows remote attackers to execute arbitrary SQL via an imported file.

    Published: 4 Mar 2005
    4.3
    Medium

    CVE-2005-0648

    Last Modified: 16 Apr 2026

    Multiple vulnerabilities in Pixel-Apes SafeHTML before 1.3.0 allow remote attackers to bypass cross-site scripting (XSS) protection via (1) "decimal HTML entities" or (2) "the \x00 symbol."

    Published: 4 Mar 2005
    4.3
    Medium

    CVE-2005-0649

    Last Modified: 16 Apr 2026

    Pixel-Apes SafeHTML before 1.2.1 allows remote attackers to bypass cross-site scripting (XSS) protection via "hexadecimal HTML entities."

    Published: 4 Mar 2005
    7.5
    High

    CVE-2005-0646

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in auth.php in paNews 2.0.4b allows remote attackers to execute arbitrary SQL via the mysql_prefix parameter.

    Published: 4 Mar 2005
    7.5
    High

    CVE-2005-0668

    Last Modified: 16 Apr 2026

    Unknown vulnerability in HTTP Anti Virus Proxy (HAVP) before 0.51 prevents viruses from being properly detected in certain files such as (1) .CAB or (2) .ZIP files.

    Published: 4 Mar 2005
    7.5
    High

    CVE-2005-0634

    Last Modified: 16 Apr 2026

    Buffer overflow in Golden FTP Server 1.92 allows remote attackers to execute arbitrary code via a long USER command.

    Published: 4 Mar 2005
    10
    Critical

    CVE-2005-0635

    Last Modified: 16 Apr 2026

    Buffer overflow in Foxmail Server 2.0 allows remote attackers to execute arbitrary code via a long USER command.

    Published: 4 Mar 2005
    5
    Medium

    CVE-2005-0718

    Last Modified: 16 Apr 2026

    Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a (1) PUT or (2) POST request, which causes Squid to access previously freed memory.

    Published: 4 Mar 2005
    7.5
    High

    CVE-2005-1345

    Last Modified: 16 Apr 2026

    Squid 2.5.STABLE9 and earlier does not trigger a fatal error when it identifies missing or invalid ACLs in the http_access configuration, which could lead to less restrictive ACLs than intended by the administrator.

    Published: 4 Mar 2005
    7.5
    High

    CVE-2005-0671

    Last Modified: 16 Apr 2026

    Format string vulnerability in Carsten's 3D Engine (Ca3DE), March 2004 version and earlier, allows remote attackers to execute arbitrary code via format string specifiers in a command.

    Published: 3 Mar 2005
    7.5
    High

    CVE-2005-0614

    Last Modified: 16 Apr 2026

    sessions.php in phpBB 2.0.12 and earlier allows remote attackers to gain administrator privileges via the autologinid value in a cookie.

    Published: 3 Mar 2005