CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2005-0674

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the News module for paBox 1.6 allows remote attackers to inject arbitrary web script or HTML via the text hidden parameter in an HTTP POST request.

    Published: 3 Mar 2005
    7.5
    High

    CVE-2005-0617

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in dl-search.php in PostNuke 0.750 and 0.760-RC2 allows remote attackers to execute arbitrary SQL commands via the show parameter.

    Published: 2 Mar 2005
    5
    Medium

    CVE-2005-0621

    Last Modified: 16 Apr 2026

    Scrapland 1.0 and earlier allows remote attackers to cause a denial of service (server termination) by triggering an error, which is treated as a fatal error by the server, as demonstrated using (1) signed integers for size values, (2) an invalid model, (3) a "newpos" value that is less than or equal to a size value, or (4) partial packets.

    Published: 2 Mar 2005
    7.5
    High

    CVE-2005-0639

    Last Modified: 16 Apr 2026

    Multiple vulnerabilities in xli before 1.17 may allow remote attackers to execute arbitrary code via "buffer management errors" from certain image properties, some of which may be related to integer overflows in PPM files.

    Published: 2 Mar 2005
    4.6
    Medium

    CVE-2005-0581

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Computer Associates (CA) License Client and Server 0.1.0.15 allow remote attackers to execute arbitrary code via (1) certain long fields in the Checksum item in a GCR request, (2) a long IP address, hostname, or netmask values in a GCR request, (3) a long last parameter in a GETCONFIG packet, or (4) long values in a request with an invalid format.

    Published: 2 Mar 2005
    6.4
    Medium

    CVE-2005-0618

    Last Modified: 16 Apr 2026

    The SMTP binding function in Symantec Firewall/VPN Appliance 200/200R firmware after 1.5Z and before 1.68, Gateway Security 360/360R and 460/460R firmware before vuild 858, and Nexland Pro800turbo, when configured for load balancing between two WANs, might send SMTP traffic to a trusted network through an untrusted network.

    Published: 2 Mar 2005
    4.6
    Medium

    CVE-2005-0640

    Last Modified: 16 Apr 2026

    Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 does not properly initialize the "Change Credentials for Database" window, which allows local users to recover the SQL Admin password via certain methods.

    Published: 2 Mar 2005
    10
    Critical

    CVE-2005-0582

    Last Modified: 16 Apr 2026

    Buffer overflow in Computer Associates (CA) License Client 0.1.0.15 allows remote attackers to execute arbitrary code via a long filename in a PUTOLF request.

    Published: 2 Mar 2005
    7.5
    High

    CVE-2005-0612

    Last Modified: 16 Apr 2026

    Cisco IP/VC Videoconferencing System 3510, 3520, 3525 and 3530 contain hard-coded default SNMP community strings, which allows remote attackers to gain access, cause a denial of service, and modify configuration.

    Published: 2 Mar 2005
    7.5
    High

    CVE-2005-0615

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in (1) index.php, (2) modules.php, or (3) admin.php in PostNuke 0.760-RC2 allow remote attackers to execute arbitrary SQL code via the catid parameter.

    Published: 2 Mar 2005
    2.1
    Low

    CVE-2005-0620

    Last Modified: 16 Apr 2026

    Einstein 1.0 stores credit card information in plaintext in the world-readable wallets.dat file, which allows local users to steal the information.

    Published: 2 Mar 2005
    7.5
    High

    CVE-2005-0633

    Last Modified: 16 Apr 2026

    Buffer overflow in Trillian 3.0 and Pro 3.0 allows remote attackers to execute arbitrary code via a crafted PNG image file.

    Published: 2 Mar 2005
    5
    Medium

    CVE-2005-0583

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Computer Associates (CA) License Client 0.1.0.15 allows remote attackers to create arbitrary files via .. (dot dot) sequences in a PUTOLF request.

    Published: 2 Mar 2005
    10
    Critical

    CVE-2005-0636

    Last Modified: 16 Apr 2026

    Format string vulnerability in Foxmail Server 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the USER command.

    Published: 2 Mar 2005
    4.3
    Medium

    CVE-2005-0641

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Reporter for Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 allows remote attackers to inject arbitrary HTML or web script via the (1) name or (2) description in a report template.

    Published: 2 Mar 2005
    2.6
    Low

    CVE-2005-0626

    Last Modified: 16 Apr 2026

    Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-Cookie recommendations for handling cookies in caches, may cause Set-Cookie headers to be sent to other users, which allows attackers to steal the related cookies.

    Published: 2 Mar 2005
    7.5
    High

    CVE-2005-0595

    Last Modified: 16 Apr 2026

    Buffer overflow in ext.dll in BadBlue 2.55 allows remote attackers to execute arbitrary code via a long mfcisapicommand parameter.

    Published: 1 Mar 2005
    5
    Medium

    CVE-2005-0597

    Last Modified: 16 Apr 2026

    Cisco devices running Application and Content Networking System (ACNS) 5.0 before 5.0.17.6 and 5.1 before 5.1.11.6 allow remote attackers to cause a denial of service (process restart) via a "crafted TCP connection."

    Published: 1 Mar 2005
    7.5
    High

    CVE-2005-0601

    Last Modified: 16 Apr 2026

    Cisco devices running Application and Content Networking System (ACNS) 4.x, 5.0, 5.1, or 5.2 use a default password when the setup dialog has not been run, which allows remote attackers to gain access.

    Published: 1 Mar 2005
    2.1
    Low

    CVE-2005-0596

    Last Modified: 16 Apr 2026

    PHP 4 (PHP4) allows attackers to cause a denial of service (daemon crash) by using the readfile function on a file whose size is a multiple of the page size.

    Published: 1 Mar 2005
    4.6
    Medium

    CVE-2005-0604

    Last Modified: 16 Apr 2026

    lnss.exe in GFI Languard Network Security Scanner 5.0 stores the username and password in memory in plaintext, which could allow local administrators to obtain domain administrator credentials.

    Published: 1 Mar 2005
    4.3
    Medium

    CVE-2005-0606

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in settings.inc.php for CubeCart 2.0.0 through 2.0.5, as used in multiple PHP files, allows remote attackers to inject arbitrary HTML or web script via the (1) cat_id, (2) PHPSESSID, (3) view_doc, (4) product, (5) session, (6) catname, (7) search, or (8) page parameters.

    Published: 1 Mar 2005
    5
    Medium

    CVE-2005-0622

    Last Modified: 16 Apr 2026

    RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to view the PHP source code via an HTTP GET request for a filename with a trailing (1) . (dot) or (2) space.

    Published: 1 Mar 2005
    7.5
    High

    CVE-2005-0623

    Last Modified: 16 Apr 2026

    Buffer overflow in RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to execute arbitrary code via a long URL.

    Published: 1 Mar 2005
    4.3
    Medium

    CVE-2005-0628

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Forumwa 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter in search.php or the (2) body or (3) subject of a forum message.

    Published: 1 Mar 2005
    4.3
    Medium

    CVE-2005-0629

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in profile.php in 427BB 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) Avatar parameters.

    Published: 1 Mar 2005
    2.1
    Low

    CVE-2005-0630

    Last Modified: 16 Apr 2026

    sendpm.php in PBLang 4.63 allows remote authenticated users to read arbitrary files via a full pathname in the orig parameter.

    Published: 1 Mar 2005
    2.1
    Low

    CVE-2005-0631

    Last Modified: 16 Apr 2026

    delpm.php in PBLang 4.63 allows remote authenticated users to delete arbitrary PM files by modifying the "id" and "a" parameters.

    Published: 1 Mar 2005
    5
    Medium

    CVE-2005-0632

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP code via the path parameter.

    Published: 1 Mar 2005
    5
    Medium

    CVE-2005-0599

    Last Modified: 16 Apr 2026

    Cisco devices running Application and Content Networking System (ACNS) 4.x, 5.0, or 5.1 before 5.1.11.6 allow remote attackers to cause a denial of service (CPU consumption) via malformed IP packets.

    Published: 1 Mar 2005
    6.2
    Medium

    CVE-2005-0602

    Last Modified: 16 Apr 2026

    Unzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privileges.

    Published: 1 Mar 2005
    5
    Medium

    CVE-2005-0607

    Last Modified: 16 Apr 2026

    CubeCart 2.0.0 through 2.0.5 allows remote attackers to determine the full path of the server via direct calls without parameters to (1) information.php, (2) language.php, (3) list_docs.php, (4) popular_prod.php, (5) sale.php, (6) subfooter.inc.php, (7) subheader.inc.php, (8) cat_navi.php, or (9) check_sum.php, which reveals the path in a PHP error message.

    Published: 1 Mar 2005
    7.5
    High

    CVE-2005-0605

    Last Modified: 16 Apr 2026

    scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value that leads to a buffer overflow.

    Published: 1 Mar 2005
    Unknown

    CVE-2005-0940

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-0490. Reason: This candidate was inadvertently referenced in a vendor advisory due to a typo. Notes: All CVE users should reference CVE-2005-0490 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Feb 2005
    5
    Medium

    CVE-2004-0945

    Last Modified: 16 Apr 2026

    The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 allows remote authenticated users to cause a denial of service (resource exhaustion) via a large number of active sessions, which exceeds ICP's maximum.

    Published: 28 Feb 2005
    7.5
    High

    CVE-2005-0608

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in server.cpp for WebMod 0.47 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a POST request with a Content-Length that is less than the amount of data that is actually sent.

    Published: 28 Feb 2005
    6.5
    Medium

    CVE-2005-0587

    Last Modified: 16 Apr 2026

    Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the first .LNK file.

    Published: 28 Feb 2005
    2.1
    Low

    CVE-2005-0624

    Last Modified: 16 Apr 2026

    reportbug before 2.62 creates the .reportbugrc configuration file with world-readable permissions, which allows local users to obtain email smarthost passwords.

    Published: 28 Feb 2005
    5
    Medium

    CVE-2005-0603

    Last Modified: 16 Apr 2026

    viewtopic.php in phpBB 2.0.12 and earlier allows remote attackers to obtain sensitive information via a highlight parameter containing invalid regular expression syntax, which reveals the path in a PHP error message.

    Published: 28 Feb 2005
    5
    Medium

    CVE-2005-0613

    Last Modified: 16 Apr 2026

    Unknown vulnerability in FCKeditor 2.0 RC2, when used with PHP-Nuke, allows remote attackers to upload arbitrary files.

    Published: 28 Feb 2005
    2.1
    Low

    CVE-2005-0619

    Last Modified: 16 Apr 2026

    Einstein 1.0.1 stores sensitive information such as usernames and passwords in plaintext in the registry, which allows local users to gain privileges.

    Published: 28 Feb 2005
    4.3
    Medium

    CVE-2005-0616

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Download module for PostNuke 0.750 and 0.760-RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) Program name, (2) File link, (3) Author name (4) Author e-mail address, (5) File size, (6) Version, or (7) Home page variables.

    Published: 28 Feb 2005
    2.1
    Low

    CVE-2005-0625

    Last Modified: 16 Apr 2026

    reportbug 3.2 includes settings from .reportbugrc in bug reports, which exposes sensitive information such as smtpuser and smtppasswd.

    Published: 28 Feb 2005
    4.6
    Medium

    CVE-2005-0205

    Last Modified: 16 Apr 2026

    KPPP 2.1.2 in KDE 3.1.5 and earlier, when setuid root without certain wrappers, does not properly close a privileged file descriptor for a domain socket, which allows local users to read and write to /etc/hosts and /etc/resolv.conf and gain control over DNS name resolution by opening a number of file descriptors before executing kppp.

    Published: 28 Feb 2005
    5
    Medium

    CVE-2005-0255

    Last Modified: 16 Apr 2026

    String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird before 1.0.2, such as the nsTSubstring_CharT::Replace function, do not properly check the return values of other functions that resize the string, which allows remote attackers to cause a denial of service and possibly execute arbitrary code by forcing an out-of-memory state that causes a reallocation to fail and return a pointer to a fixed address, which leads to heap corruption.

    Published: 28 Feb 2005
    7.5
    High

    CVE-2005-0565

    Last Modified: 16 Apr 2026

    The Announce module in phpWebSite 0.10.0 and earlier allows remote attackers to execute arbitrary PHP code by setting the Image field to reference a PHP file whose name contains a .gif.php extension.

    Published: 27 Feb 2005
    7.5
    High

    CVE-2005-0575

    Last Modified: 16 Apr 2026

    Buffer overflow in Stormy Studios Knet 1.04c and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP GET request.

    Published: 27 Feb 2005
    7.5
    High

    CVE-2005-0567

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in phpMyAdmin 2.6.1 allow remote attackers to execute arbitrary PHP code by modifying the (1) theme parameter to phpmyadmin.css.php or (2) cfg[Server][extension] parameter to database_interface.lib.php to reference a URL on a remote web server that contains the code.

    Published: 27 Feb 2005
    3.6
    Low

    CVE-2005-0576

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Standard Type Services Framework (STSF) Font Server Daemon (stfontserverd) in Solaris 9 allows local users to modify or delete arbitrary files.

    Published: 27 Feb 2005
    5
    Medium

    CVE-2005-0568

    Last Modified: 16 Apr 2026

    Soldier of Fortune II 1.03 gold allows remote attackers to cause a denial of service (application crash) via a large cl_guid value, which results in an invalid pointer dereference.

    Published: 27 Feb 2005