CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2005-0569

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in PunBB 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) language parameter to register.php, (2) change email feature in profile.php, (3) posts or (4) topics parameter to moderate.php.

    Published: 27 Feb 2005
    5
    Medium

    CVE-2005-0570

    Last Modified: 16 Apr 2026

    profile.php in PunBB 1.2.1 allows remote attackers to cause a denial of service (account lockout) by setting the user's password to NULL.

    Published: 27 Feb 2005
    5
    Medium

    CVE-2005-0571

    Last Modified: 16 Apr 2026

    admin_loader.php in PunBB 1.2.1 allows remote attackers to read arbitrary files via the plugin parameter.

    Published: 27 Feb 2005
    5
    Medium

    CVE-2005-0572

    Last Modified: 16 Apr 2026

    index.php in phpWebSite 0.10.0 and earlier allows remote attackers to obtain sensitive information via an invalid SEA_search_module parameter, which reveals the path in a PHP error message.

    Published: 27 Feb 2005
    5
    Medium

    CVE-2005-0573

    Last Modified: 16 Apr 2026

    Gaim 1.1.3 on Windows systems allows remote attackers to cause a denial of service (client crash) via a file transfer in which the filename contains "(" or ")" (parenthesis) characters.

    Published: 27 Feb 2005
    5.1
    Medium

    CVE-2005-0577

    Last Modified: 16 Apr 2026

    Format string vulnerability in DNA MKBold-MKItalic 0.06_1 and earlier allows remote attackers to execute arbitrary code via crafted BDF font files.

    Published: 27 Feb 2005
    5
    Medium

    CVE-2005-0574

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in CIS WebServer 3.5.13 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the URL.

    Published: 27 Feb 2005
    7.2
    High

    CVE-2005-0867

    Last Modified: 16 Apr 2026

    Integer overflow in Linux kernel 2.6 allows local users to overwrite kernel memory by writing to a sysfs file.

    Published: 27 Feb 2005
    2.1
    Low

    CVE-2005-0580

    Last Modified: 16 Apr 2026

    cmd5checkpw, when running setuid, does not properly drop privileges before calling the execvp function, which allows local users to read the poppasswd file.

    Published: 25 Feb 2005
    7.5
    High

    CVE-2005-0107

    Last Modified: 16 Apr 2026

    bsmtpd 2.3 and earlier does not properly sanitize e-mail addresses, which allows remote attackers to execute arbitrary commands.

    Published: 25 Feb 2005
    7.2
    High

    CVE-2005-0545

    Last Modified: 16 Apr 2026

    Microsoft Windows XP Pro SP2 and Windows 2000 Server SP4 running Active Directory allow local users to bypass group policies that restrict access to hidden drives by using the browse feature in Office 10 applications such as Word or Excel, or using a flash drive. NOTE: this issue has been disputed in a followup post.

    Published: 25 Feb 2005
    5
    Medium

    CVE-2005-0256

    Last Modified: 16 Apr 2026

    The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir command.

    Published: 25 Feb 2005
    4.6
    Medium

    CVE-2005-0579

    Last Modified: 16 Apr 2026

    nxagent in FreeNX before 0.2.8 does not properly handle when the XAUTHORITY environment variable is not set, which allows local users to access the X server without X authentication.

    Published: 25 Feb 2005
    5.1
    Medium

    CVE-2005-0527

    Last Modified: 16 Apr 2026

    Firefox 1.0 allows remote attackers to execute arbitrary code via plugins that load "privileged content" into frames, as demonstrated using certain XUL events when a user drags a scrollbar two times, aka "Firescrolling."

    Published: 25 Feb 2005
    4.3
    Medium

    CVE-2005-0543

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cfg[BgcolorOne], or strServerChoice parameters in select_server.lib.php, (2) the bg_color or row_no parameters in display_tbl_links.lib.php, the left_font_family parameter in theme_left.css.php, or the right_font_family parameter in theme_right.css.php.

    Published: 24 Feb 2005
    4.6
    Medium

    CVE-2005-0547

    Last Modified: 16 Apr 2026

    Unknown vulnerability in ftpd on HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23 allows remote authenticated users to gain "unauthorized access to files."

    Published: 24 Feb 2005
    4.6
    Medium

    CVE-2005-0542

    Last Modified: 16 Apr 2026

    saveUser.do in Cyclades AlterPath Manager (APM) Console Server 1.2.1 allows local users to gain privileges by setting the adminUser parameter to true.

    Published: 24 Feb 2005
    7.5
    High

    CVE-2005-0541

    Last Modified: 16 Apr 2026

    consoleConnect.jsp in Cyclades AlterPath Manager (APM) Console Server 1.2.1 allows remote attackers to connect to arbitrary consoles by modifying the consolename parameter.

    Published: 24 Feb 2005
    5
    Medium

    CVE-2005-0540

    Last Modified: 16 Apr 2026

    Cyclades AlterPath Manager (APM) Console Server 1.2.1 allows remote attackers to obtain sensitive information via a direct request to the /about.html page.

    Published: 24 Feb 2005
    5
    Medium

    CVE-2005-0598

    Last Modified: 16 Apr 2026

    The RealServer RealSubscriber on Cisco devices running Application and Content Networking System (ACNS) 5.1 allow remote attackers to cause a denial of service (CPU consumption) via malformed packets.

    Published: 24 Feb 2005
    7.5
    High

    CVE-2005-0533

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Trend Micro AntiVirus Library VSAPI before 7.510, as used in multiple Trend Micro products, allows remote attackers to execute arbitrary code via a crafted ARJ file with long header file names that modify pointers within a structure.

    Published: 24 Feb 2005
    4.3
    Medium

    CVE-2005-0534

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allow remote attackers to inject arbitrary web script.

    Published: 24 Feb 2005
    5
    Medium

    CVE-2005-0536

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to delete arbitrary files or determine file existence via a parameter related to image deletion.

    Published: 24 Feb 2005
    5
    Medium

    CVE-2005-0544

    Last Modified: 16 Apr 2026

    phpMyAdmin 2.6.1 allows remote attackers to obtain the full path of the server via direct requests to (1) sqlvalidator.lib.php, (2) sqlparser.lib.php, (3) select_theme.lib.php, (4) select_lang.lib.php, (5) relation_cleanup.lib.php, (6) header_meta_style.inc.php, (7) get_foreign.lib.php, (8) display_tbl_links.lib.php, (9) display_export.lib.php, (10) db_table_exists.lib.php, (11) charset_conversion.lib.php, (12) ufpdf.php, (13) mysqli.dbi.lib.php, (14) setup.php, or (15) cookie.auth.lib.php, which reveals the path in a PHP error message.

    Published: 24 Feb 2005
    5
    Medium

    CVE-2005-0600

    Last Modified: 16 Apr 2026

    Cisco devices running Application and Content Networking System (ACNS) 5.0, 5.1 before 5.1.13.7, or 5.2 before 5.2.3.9 allow remote attackers to cause a denial of service (bandwidth consumption) via "crafted IP packets" that are continuously forwarded.

    Published: 24 Feb 2005
    2.1
    Low

    CVE-2005-0532

    Last Modified: 16 Apr 2026

    The reiserfs_copy_from_user_to_file_region function in reiserfs/file.c for Linux kernel 2.6.10 and 2.6.11 before 2.6.11-rc4, when running on 64-bit architectures, may allow local users to trigger a buffer overflow as a result of casting discrepancies between size_t and int data types.

    Published: 24 Feb 2005
    5
    Medium

    CVE-2005-0538

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in (1) GinpPictureServlet.java and (2) PicCollection.java in ginp (Java Photo Gallery Web Application) before 0.22 allows remote attackers to read arbitrary files.

    Published: 24 Feb 2005
    4.6
    Medium

    CVE-2005-0539

    Last Modified: 16 Apr 2026

    Unknown vulnerability in IBM Hardware Management Console (HMC) before 4.4 for POWER5 servers allows local users to gain privileges, related to the Guided Setup Wizard.

    Published: 24 Feb 2005
    2.1
    Low

    CVE-2005-0578

    Last Modified: 16 Apr 2026

    Firefox before 1.0.1 and Mozilla Suite before 1.7.6 use a predictable filename for the plugin temporary directory, which allows local users to delete arbitrary files of other users via a symlink attack on the plugtmp directory.

    Published: 24 Feb 2005
    5.1
    Medium

    CVE-2005-0455

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the CSmil1Parser::testAttributeFailed function in smlparse.cpp for RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1 allows remote attackers to execute arbitrary code via a .SMIL file with a large system-screen-size value.

    Published: 24 Feb 2005
    5.1
    Medium

    CVE-2005-0611

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1, allows remote attackers to execute arbitrary code via .WAV files.

    Published: 24 Feb 2005
    5
    Medium

    CVE-2005-0589

    Last Modified: 16 Apr 2026

    The Form Fill feature in Firefox before 1.0.1 allows remote attackers to steal potentially sensitive information via an input control that monitors the values that are generated by the autocomplete capability.

    Published: 24 Feb 2005
    5
    Medium

    CVE-2005-0588

    Last Modified: 16 Apr 2026

    Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.

    Published: 24 Feb 2005
    2.6
    Low

    CVE-2005-0584

    Last Modified: 16 Apr 2026

    Firefox before 1.0.1 and Mozilla before 1.7.6, when displaying the HTTP Authentication dialog, do not change the focus to the tab that generated the prompt, which could facilitate spoofing and phishing attacks.

    Published: 24 Feb 2005
    5
    Medium

    CVE-2005-0208

    Last Modified: 16 Apr 2026

    The HTML parsing functions in Gaim before 1.1.4 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes "an invalid memory access," a different vulnerability than CVE-2005-0473.

    Published: 24 Feb 2005
    5
    Medium

    CVE-2005-0590

    Last Modified: 16 Apr 2026

    The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a long "user:pass" sequence in the URL, which appears before the real hostname.

    Published: 24 Feb 2005
    2.6
    Low

    CVE-2005-0591

    Last Modified: 16 Apr 2026

    Firefox before 1.0.1 allows remote attackers to spoof the (1) security and (2) download modal dialog boxes, which could be used to trick users into executing script or downloading and executing a file, aka "Firespoofing."

    Published: 24 Feb 2005
    7.5
    High

    CVE-2005-0592

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla before 1.7.6 might allow remote attackers to cause a denial of service (crash) or execute arbitrary code via invalid sequences in a UTF8 encoded string that result in a zero length value.

    Published: 24 Feb 2005
    2.6
    Low

    CVE-2005-0593

    Last Modified: 16 Apr 2026

    Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" lock icon via (1) a web site that does not finish loading, which shows the lock of the previous site, (2) a non-HTTP server that uses SSL, which causes the lock to be displayed when the SSL handshake is completed, or (3) a URL that generates an HTTP 204 error, which updates the icon and location information but does not change the display of the original site.

    Published: 24 Feb 2005
    2.6
    Low

    CVE-2005-0586

    Last Modified: 16 Apr 2026

    Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to spoof the extensions of files to download via the Content-Disposition header, which could be used to trick users into downloading dangerous content.

    Published: 24 Feb 2005
    4.3
    Medium

    CVE-2005-0526

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PBLang 4.65 allow remote attackers to inject arbitrary web script or HTML via (1) the search string to search.php, (2) the subject of a PM, which is processed by pm.php, or (3) the body of a PM, which is processed by pmpshow.php.

    Published: 23 Feb 2005
    2.1
    Low

    CVE-2005-0517

    Last Modified: 16 Apr 2026

    PeerFTP_5 stores sensitive information such as passwords in plaintext in the PeerFTP.ini files, which allows local users to gain privileges.

    Published: 23 Feb 2005
    2.1
    Low

    CVE-2004-0481

    Last Modified: 16 Apr 2026

    The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary files via a symlink attack on the KCS_ClogFile file.

    Published: 23 Feb 2005
    2.1
    Low

    CVE-2005-0518

    Last Modified: 16 Apr 2026

    eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local users to gain privileges via the proxy_user and proxy_password values.

    Published: 23 Feb 2005
    10
    Critical

    CVE-2005-0520

    Last Modified: 16 Apr 2026

    ArGoSoft FTP Server before 1.4.2.8 allows remote attackers to read arbitrary files via shortcut (.LNK) files in the SITE COPY command, a different vulnerability than CVE-2005-0519.

    Published: 23 Feb 2005
    7.5
    High

    CVE-2005-0516

    Last Modified: 16 Apr 2026

    The ImageGalleryPlugin (ImageGalleryPlugin.pm) in Twiki allows remote attackers to execute arbitrary commands via certain commands that generate thumbnails.

    Published: 23 Feb 2005
    2.1
    Low

    CVE-2005-0521

    Last Modified: 16 Apr 2026

    SendLink 1.5 stores sensitive information, possibly including passwords, in plaintext in the data.eat file, which allows local users to gain privileges.

    Published: 23 Feb 2005
    4.6
    Medium

    CVE-2005-0522

    Last Modified: 16 Apr 2026

    Chat Anywhere 2.72a stores sensitive information such as passwords in plaintext in the .INI file for a chatroom, which allows local users to gain privileges.

    Published: 23 Feb 2005
    7.5
    High

    CVE-2005-0523

    Last Modified: 16 Apr 2026

    Format string vulnerability in ProZilla 1.3.7.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the Location header.

    Published: 23 Feb 2005
    3.7
    Low

    CVE-2006-1174

    Last Modified: 16 Apr 2026

    useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly allows attackers to read or modify the mailbox.

    Published: 23 Feb 2005