CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2005-0161

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archive containing (1) ../ sequences or (2) absolute pathnames.

    Published: 22 Feb 2005
    2.1
    Low

    CVE-2005-0510

    Last Modified: 16 Apr 2026

    The daemon for fallback-reboot before 0.995 allows attackers to cause a denial of service (daemon exit), possibly related to verbose debug messages when the daemon is not on a tty.

    Published: 22 Feb 2005
    4.3
    Medium

    CVE-2005-0514

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Verity Ultraseek before 5.3.3 allows remote attackers to inject arbitrary HTML and web script via search parameters.

    Published: 22 Feb 2005
    6.4
    Medium

    CVE-2005-0259

    Last Modified: 16 Apr 2026

    phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file.

    Published: 22 Feb 2005
    4.6
    Medium

    CVE-2005-0504

    Last Modified: 16 Apr 2026

    Buffer overflow in the MoxaDriverIoctl function for the moxa serial driver (moxa.c) in Linux 2.2.x, 2.4.x, and 2.6.x before 2.6.22 allows local users to execute arbitrary code via a certain modified length value.

    Published: 22 Feb 2005
    5
    Medium

    CVE-2005-0258

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in (1) usercp_register.php and (2) usercp_avatar.php for phpBB 2.0.11, and possibly other versions, with gallery avatars enabled, allows remote attackers to delete (unlink) arbitrary files via "/../" sequences in the avatarselect parameter.

    Published: 22 Feb 2005
    4.3
    Medium

    CVE-2005-0509

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "<".

    Published: 22 Feb 2005
    7.5
    High

    CVE-2005-0535

    Last Modified: 16 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to perform unauthorized actions as authenticated MediaWiki users.

    Published: 22 Feb 2005
    5.1
    Medium

    CVE-2005-0160

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in unace 1.2b allow attackers to execute arbitrary code via (1) 2 overflows in ACE archives, (2) a long command line argument, or (3) certain "Ready for next volume" messages.

    Published: 22 Feb 2005
    7.5
    High

    CVE-2005-0505

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Information Resource Manager (IRM) before 1.5.2.1 allows remote attackers to have "potentially serious" impact, related to LDAP logins.

    Published: 22 Feb 2005
    5
    Medium

    CVE-2005-0506

    Last Modified: 16 Apr 2026

    The Avaya IP Office Phone Manager, and other products such as the IP Softphone, stores sensitive data in cleartext in a registry key, which allows local and possibly remote users to steal usernames and passwords and impersonate other users via keys such as Avaya\IP400\Generic.

    Published: 22 Feb 2005
    5
    Medium

    CVE-2005-0507

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in SD Server 4.0.70 and earlier allows remote attackers to read arbitrary files via .. sequences in an HTTP request.

    Published: 22 Feb 2005
    4.6
    Medium

    CVE-2005-0508

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Squiggle for Batik before 1.5.1 allows attackers to bypass certain access controls via certain features of the Rhino scripting engine due to a "script security issue."

    Published: 22 Feb 2005
    1.2
    Low

    CVE-2005-0937

    Last Modified: 16 Apr 2026

    Some futex functions in futex.c for Linux kernel 2.6.x perform get_user calls while holding the mmap_sem semaphore, which could allow local users to cause a deadlock condition in do_page_fault by triggering get_user faults while another thread is executing mmap or other functions.

    Published: 22 Feb 2005
    7.5
    High

    CVE-2005-0537

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in page.php for iGeneric (iG) Shop 1.2 may allow remote attackers to execute arbitrary SQL statements via the (1) cats, (2) l_price, or (3) u_price parameters.

    Published: 21 Feb 2005
    7.5
    High

    CVE-2005-0512

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in Tar.php in Mambo 4.5.2 allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2004-1693.

    Published: 21 Feb 2005
    7.5
    High

    CVE-2005-0511

    Last Modified: 16 Apr 2026

    misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.

    Published: 21 Feb 2005
    4.6
    Medium

    CVE-2005-0503

    Last Modified: 16 Apr 2026

    uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges.

    Published: 21 Feb 2005
    5
    Medium

    CVE-2005-0500

    Last Modified: 16 Apr 2026

    Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to spoof the domain name of a URL in a titlebar for a script-initiated popup window, which could facilitate phishing attacks.

    Published: 21 Feb 2005
    7.5
    High

    CVE-2005-0467

    Last Modified: 16 Apr 2026

    Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibly earlier versions, allow remote malicious web sites to execute arbitrary code via SFTP responses that corrupt the heap after insufficient memory has been allocated.

    Published: 21 Feb 2005
    10
    Critical

    CVE-2005-0491

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Knox Arkeia Server Backup 5.3.x allows remote attackers to execute arbitrary code via a long type 77 request.

    Published: 21 Feb 2005
    7.5
    High

    CVE-2005-0498

    Last Modified: 16 Apr 2026

    Gigafast router (aka CompUSA router) allows remote attackers to gain sensitive information and bypass the login page via a direct request to backup.cfg, which reveals the administrator password in plaintext.

    Published: 21 Feb 2005
    7.5
    High

    CVE-2005-0501

    Last Modified: 16 Apr 2026

    Buffer overflow in Bontago 1.1 and earlier allows remote attackers to execute arbitrary code via a long nickname.

    Published: 21 Feb 2005
    2.6
    Low

    CVE-2005-0492

    Last Modified: 16 Apr 2026

    Adobe Acrobat Reader 6.0.3 and 7.0.0 allows remote attackers to cause a denial of service (application crash) via a PDF file that contains a negative Count value in the root page node.

    Published: 21 Feb 2005
    5
    Medium

    CVE-2005-0493

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in bizmail.cgi in Biz Mail Form before 2.2 allows remote attackers to bypass the email check and send spam e-mail via CRLF sequences and forged mail headers in the email parameter.

    Published: 21 Feb 2005
    7.5
    High

    CVE-2005-0494

    Last Modified: 16 Apr 2026

    The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly validate the password before performing changes, which allows remote attackers on the LAN to gain access via a direct POST request.

    Published: 21 Feb 2005
    9.8
    Critical

    CVE-2005-0496

    Last Modified: 16 Apr 2026

    Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the file system and possibly execute arbitrary commands.

    Published: 21 Feb 2005
    7.2
    High

    CVE-2005-0497

    Last Modified: 16 Apr 2026

    ADP Elite System Max 9000 allows remote authenticated users to gain privileges by uploading a .profile that sets the ADPROOT environment variable to the root directory.

    Published: 21 Feb 2005
    8.8
    High

    CVE-2005-0490

    Last Modified: 16 Apr 2026

    Multiple stack-based buffer overflows in libcURL and cURL 7.12.1, and possibly other versions, allow remote malicious web servers to execute arbitrary code via base64 encoded replies that exceed the intended buffer lengths when decoded, which is not properly handled by (1) the Curl_input_ntlm function in http_ntlm.c during NTLM authentication or (2) the Curl_krb_kauth and krb4_auth functions in krb4.c during Kerberos authentication.

    Published: 21 Feb 2005
    5
    Medium

    CVE-2005-0499

    Last Modified: 16 Apr 2026

    Gigafast router (aka CompUSA router) with the DNS proxy option enabled allows remote attackers to cause a denial of service via malformed DNS queries.

    Published: 20 Feb 2005
    5
    Medium

    CVE-2005-0481

    Last Modified: 16 Apr 2026

    TrackerCam 5.12 and earlier allows remote attackers to read log files via the fn parameter in a direct request to the ComGetLogFile.php3 script.

    Published: 19 Feb 2005
    5
    Medium

    CVE-2005-0482

    Last Modified: 16 Apr 2026

    TrackerCam 5.12 and earlier allows remote attackers to cause a denial of service (crash) via (1) a large number of connections with a negative Content-Length header, possibly triggering an integer signedness error, or (2) a large amount of data.

    Published: 19 Feb 2005
    6.4
    Medium

    CVE-2005-0474

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the user_valid_crypt function in user.php in WebCalendar 0.9.45 allows remote attackers to execute arbitrary SQL commands via an encoded webcalendar_session cookie.

    Published: 19 Feb 2005
    6.4
    Medium

    CVE-2005-0475

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQL code via the (1) offset, (2) limit, (3) order, or (4) orderby parameter to question.php, (5) offset parameter to answer.php, (6) search_item parameter to search.php, (7) cat_id, (8) cid, or (9) id parameter to comment.php.

    Published: 19 Feb 2005
    5
    Medium

    CVE-2005-0483

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in sitenfo.sh, sitezipchk.sh, and siteziplist.sh in Glftpd 1.26 to 2.00 allow remote authenticated users to (1) determine the existence of arbitrary files, (2) list files in restricted directories, or (3) read arbitrary files from within ZIP or gzip files, via .. (dot dot) sequences and globbing ("*") characters in a SITE NFO command.

    Published: 19 Feb 2005
    7.5
    High

    CVE-2005-0513

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in mail_autocheck.php in the Email This Entry add-on for pMachine Pro 2.4, and possibly other versions including pMachine Free, allows remote attackers to execute arbitrary PHP code by directly requesting mail_autocheck.php and modifying the pm_path parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2003-1086.

    Published: 19 Feb 2005
    5
    Medium

    CVE-2005-0470

    Last Modified: 16 Apr 2026

    Buffer overflow in wpa_supplicant before 0.2.7 allows remote attackers to cause a denial of service (segmentation fault) via invalid EAPOL-Key packet data.

    Published: 19 Feb 2005
    5
    Medium

    CVE-2005-0471

    Last Modified: 16 Apr 2026

    Sun Java JRE 1.1.x through 1.4.x writes temporary files with long filenames that become predictable on a file system that uses 8.3 style short names, which allows remote attackers to write arbitrary files to known locations and facilitates the exploitation of vulnerabilities in applications that rely on unpredictable file names.

    Published: 19 Feb 2005
    4.3
    Medium

    CVE-2005-0476

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in hpm_guestbook.cgi allows remote attackers to inject arbitrary web script or HTML by posting a message.

    Published: 19 Feb 2005
    4.3
    Medium

    CVE-2005-0477

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote attackers to inject arbitrary web script via (1) a signature file or (2) a message post containing an IMG tag within a COLOR tag whose style is set to background:url.

    Published: 19 Feb 2005
    5
    Medium

    CVE-2005-0478

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in TrackerCam 5.12 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) an HTTP request with a long User-Agent header or (2) a long argument to an arbitrary PHP script.

    Published: 19 Feb 2005
    5
    Medium

    CVE-2005-0479

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in ComGetLogFile.php3 for TrackerCam 5.12 and earlier allows remote attackers to read arbitrary files via ".." sequences and (1) "/" slash), (2) "\" (backslash), or (3) hex-encoded characters in the fn parameter.

    Published: 19 Feb 2005
    4.3
    Medium

    CVE-2005-0480

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in TrackerCam 5.12 and earlier allows remote attackers to inject arbitrary HTML or web script via the login request, which is recorded in a log file but not properly handled when the administrator views the log file.

    Published: 19 Feb 2005
    7.5
    High

    CVE-2005-0484

    Last Modified: 16 Apr 2026

    Format string vulnerability in gprostats for GProFTPD before 8.1.9 may allow remote attackers to execute arbitrary code via an FTP transfer with a crafted filename that causes format string specifiers to be inserted into the ProFTPD transfer log.

    Published: 19 Feb 2005
    6.8
    Medium

    CVE-2005-0485

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in comment.php for paNews 2.0b4 for PHP Arena allows remote attackers to inject arbitrary HTML and web script via the showpost parameter.

    Published: 19 Feb 2005
    5
    Medium

    CVE-2005-0486

    Last Modified: 16 Apr 2026

    Tarantella Secure Global Desktop Enterprise Edition 4.00 and 3.42, and Tarantella Enterprise 3 3.40 and 3.30, when using RSA SecurID and multiple users have the same username, reveals sensitive information during authentication, which allows remote attackers to identify valid usernames and the authentication scheme.

    Published: 19 Feb 2005
    6.8
    Medium

    CVE-2005-0487

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php for Kayako ESupport 2.3.1, and possibly other versions, allows remote attackers to inject arbitrary HTML and web script via the nav parameter.

    Published: 19 Feb 2005
    4.3
    Medium

    CVE-2005-0495

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in ZeroBoard allows remote attackers to inject arbitrary web script or HTML via the (1) sn1, (2) year, or (3) page parameter to zboard.php or (4) filename to view_image.php.

    Published: 19 Feb 2005
    10
    Critical

    CVE-2005-0519

    Last Modified: 16 Apr 2026

    ArGoSoft FTP Server before 1.4.2.7 allows remote attackers to read arbitrary files by uploading a ZIP file containing a shortcut (.LNK) file, using SITE UNZIP to extract the .LNK file onto the server, then accessing the file, a different vulnerability than CVE-2005-0520.

    Published: 18 Feb 2005
    7.5
    High

    CVE-2005-0158

    Last Modified: 16 Apr 2026

    Format string vulnerability in bidwatcher before 1.3.17 allows remote malicious web servers from eBay, or a spoofed eBay server, to cause a denial of service and possibly execute arbitrary code via certain responses.

    Published: 18 Feb 2005