CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2005-0242

    Last Modified: 16 Apr 2026

    The Audio Setup Wizard (asw.dll) in Yahoo! Messenger 6.0.0.1750, and possibly other versions, allows attackers to arbitrary code by placing a malicious ping.exe program into the Messenger program directory, which is installed with weak default permissions.

    Published: 18 Feb 2005
    5
    Medium

    CVE-2005-0502

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Xinkaa 1.0.3 and earlier allows remote attackers to read arbitrary files via (1) ../ and (2) ..\ characters in an HTTP request.

    Published: 18 Feb 2005
    7.5
    High

    CVE-2005-0638

    Last Modified: 16 Apr 2026

    xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly quoted when calling the gunzip command.

    Published: 18 Feb 2005
    2.1
    Low

    CVE-2005-0090

    Last Modified: 16 Apr 2026

    A regression error in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch omits an "access check," which allows local users to cause a denial of service (crash).

    Published: 18 Feb 2005
    7.2
    High

    CVE-2005-0091

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when using the hugemem kernel, allows local users to read and write to arbitrary kernel memory and gain privileges via certain syscalls.

    Published: 18 Feb 2005
    2.1
    Low

    CVE-2005-0092

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when running on x86 with the hugemem kernel, allows local users to cause a denial of service (crash).

    Published: 18 Feb 2005
    5
    Medium

    CVE-2005-0243

    Last Modified: 16 Apr 2026

    Yahoo! Messenger 6.0.0.1750, and possibly other versions before 6.0.0.1921, does not properly display long filenames in file dialog boxes, which could allow remote attackers to trick users into downloading and executing programs via file names containing a large number of spaces and multiple file extensions.

    Published: 17 Feb 2005
    4
    Medium

    CVE-2005-0253

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to delete arbitrary files via a Delete action and .. (dot dot) sequences in the database_name parameter.

    Published: 17 Feb 2005
    3.7
    Low

    CVE-2005-0254

    Last Modified: 16 Apr 2026

    BibORB 1.3.2, and possibly earlier versions, does not properly enforce a restriction for uploading only PDF and PS files, which allows remote attackers to upload arbitrary files that are presented to other users with PDF or PS icons, which may trick some users into downloading and executing those files.

    Published: 17 Feb 2005
    7.5
    High

    CVE-2005-0252

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in BibORB 1.3.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the (1) Username or (2) Password.

    Published: 17 Feb 2005
    4.3
    Medium

    CVE-2005-0251

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in bibindex.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to inject arbitrary HTML and web script via the search parameter.

    Published: 17 Feb 2005
    7.2
    High

    CVE-2005-0457

    Last Modified: 16 Apr 2026

    Opera 7.54 and earlier on Gentoo Linux uses an insecure path for plugins, which could allow local users to gain privileges by inserting malicious libraries into the PORTAGE_TMPDIR (portage) temporary directory.

    Published: 17 Feb 2005
    4.3
    Medium

    CVE-2005-0458

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in contact_us.php in osCommerce 2.2-MS2 allows remote attackers to inject arbitrary web script or HTML via the enquiry parameter.

    Published: 17 Feb 2005
    5
    Medium

    CVE-2005-0459

    Last Modified: 16 Apr 2026

    phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote attackers to determine the full path of the web root via a direct request to select_lang.lib.php, which reveals the path in a PHP error message.

    Published: 17 Feb 2005
    5
    Medium

    CVE-2005-0461

    Last Modified: 16 Apr 2026

    Unknown vulnerability in NewsBruiser 2.x before 2.6.1 allows remote attackers to "take actions on comments."

    Published: 17 Feb 2005
    4.3
    Medium

    CVE-2005-0462

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in MercuryBoard 1.0.x and 1.1.x allows remote attackers to inject arbitrary HTML and web script via the f parameter.

    Published: 17 Feb 2005
    7.5
    High

    CVE-2005-0463

    Last Modified: 16 Apr 2026

    Unknown "major security flaws" in Ulog-php before 1.0, related to input validation, have unknown impact and attack vectors, probably related to SQL injection vulnerabilities in (1) host.php, (2) port.php, and (3) index.php.

    Published: 17 Feb 2005
    5
    Medium

    CVE-2005-0460

    Last Modified: 16 Apr 2026

    index.php in MercuryBoard 1.0.x and 1.1.x allows remote attackers to obtain sensitive information by setting the debug parameter.

    Published: 17 Feb 2005
    5
    Medium

    CVE-2005-0472

    Last Modified: 16 Apr 2026

    Gaim before 1.1.3 allows remote attackers to cause a denial of service (infinite loop) via malformed SNAC packets from (1) AIM or (2) ICQ.

    Published: 17 Feb 2005
    5
    Medium

    CVE-2005-0473

    Last Modified: 16 Apr 2026

    The HTML parsing functions in Gaim before 1.1.3 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes "an invalid memory access," a different vulnerability than CVE-2005-0208.

    Published: 17 Feb 2005
    5
    Medium

    CVE-2005-0450

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Sami HTTP Server 1.0.5 allows remote attackers to read arbitrary files via an HTTP request containing (1) .. (dot dot) or (2) "%2e%2e" (encoded dot dot) sequences.

    Published: 16 Feb 2005
    5
    Medium

    CVE-2005-0453

    Last Modified: 16 Apr 2026

    The buffer_urldecode function in Lighttpd 1.3.7 and earlier does not properly handle control characters, which allows remote attackers to obtain the source code for CGI and FastCGI scripts via a URL with a %00 (null) character after the file extension.

    Published: 16 Feb 2005
    10
    Critical

    CVE-2005-0011

    Last Modified: 16 Apr 2026

    Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Interface (INDI) in KDE 3.3 to 3.3.2, allow local users and remote attackers to execute arbitrary code via stack-based buffer overflows.

    Published: 16 Feb 2005
    4.6
    Medium

    CVE-2005-0105

    Last Modified: 16 Apr 2026

    Unknown vulnerability in typespeed 0.4.1 and earlier allows local users to gain privileges.

    Published: 16 Feb 2005
    7.5
    High

    CVE-2005-0363

    Last Modified: 16 Apr 2026

    awstats.pl in AWStats 4.0 and 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.

    Published: 16 Feb 2005
    4.3
    Medium

    CVE-2005-0407

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Openconf 1.04, and possibly other versions before 1.10, allows remote attackers to inject arbitrary HTML and web script via the paper title.

    Published: 16 Feb 2005
    7.5
    High

    CVE-2005-0454

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in DCP-Portal 6.1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the lcat, doc, or uid parameters to index.php, or (2) the mid or bid parameters to forums.php.

    Published: 16 Feb 2005
    5
    Medium

    CVE-2005-0451

    Last Modified: 16 Apr 2026

    Sami HTTP Server 1.0.5 allows remote attackers to cause a denial of service via an HTTP request containing two CRLF sequences, which triggers a NULL dereference.

    Published: 16 Feb 2005
    4.3
    Medium

    CVE-2005-0452

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "<".

    Published: 16 Feb 2005
    7.2
    High

    CVE-2005-0070

    Last Modified: 16 Apr 2026

    Synaesthesia 2.1 and earlier, and possibly other versions, when installed setuid root, does not drop privileges before processing configuration and mixer files, which allows local users to read arbitrary files.

    Published: 16 Feb 2005
    5.8
    Medium

    CVE-2005-0420

    Last Modified: 16 Apr 2026

    Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login via a link to the owalogon.asp application.

    Published: 15 Feb 2005
    7.5
    High

    CVE-2005-0437

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via .. (dot dot) sequences in the loadplugin parameter.

    Published: 15 Feb 2005
    6.8
    Medium

    CVE-2005-0085

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.

    Published: 15 Feb 2005
    2.1
    Low

    CVE-2005-0421

    Last Modified: 16 Apr 2026

    DelphiTurk FTP 1.0 stores usernames and passwords in the profile.dat file, which allows local users to gain privileges.

    Published: 15 Feb 2005
    5
    Medium

    CVE-2005-0425

    Last Modified: 16 Apr 2026

    Unknown vulnerability in IBM Websphere Application Server 5.0, 5.1, and 6.0 when running on Windows, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via a crafted URL that causes the page to be processed by the file serving servlet instead of the JSP engine.

    Published: 15 Feb 2005
    5
    Medium

    CVE-2005-0429

    Last Modified: 16 Apr 2026

    Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled, allows remote attackers to execute inject arbitrary PHP commands via the comma parameter.

    Published: 15 Feb 2005
    5
    Medium

    CVE-2005-0438

    Last Modified: 16 Apr 2026

    awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter.

    Published: 15 Feb 2005
    7.5
    High

    CVE-2005-0439

    Last Modified: 16 Apr 2026

    Buffer overflow in the decode_post function in ELOG before 2.5.7 allows remote attackers to execute arbitrary code via attachments with long file names.

    Published: 15 Feb 2005
    4.3
    Medium

    CVE-2005-0443

    Last Modified: 16 Apr 2026

    index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-site scripting (XSS) attacks via an invalid language parameter, which echoes the parameter in a PHP error message.

    Published: 15 Feb 2005
    5
    Medium

    CVE-2005-0447

    Last Modified: 16 Apr 2026

    Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (hang) via a flood of certain ARP packets.

    Published: 15 Feb 2005
    4.6
    Medium

    CVE-2005-0019

    Last Modified: 16 Apr 2026

    Unknown vulnerability in hztty 2.0 and earlier allows local users to execute arbitrary commands.

    Published: 15 Feb 2005
    4.6
    Medium

    CVE-2005-0159

    Last Modified: 16 Apr 2026

    The tpkg-* scripts in the toolchain-source 3.0.4 package on Debian GNU/Linux 3.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.

    Published: 15 Feb 2005
    2.1
    Low

    CVE-2005-0422

    Last Modified: 16 Apr 2026

    DelphiTurk CodeBank (aka KodBank) 3.1 and earlier stores usernames and passwords in the Codebank registry key, which allows local users to gain privileges.

    Published: 15 Feb 2005
    5
    Medium

    CVE-2005-0423

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in login.asp in ASPjar Guestbook allows remote attackers to execute arbitrary SQL commands via the password field.

    Published: 15 Feb 2005
    5
    Medium

    CVE-2005-0424

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the delete.asp program in certain versions of ASPjar Guestbook allows remote attackers to delete messages. NOTE: there is insufficient information to know if this is the same issue as CVE-2002-1730.

    Published: 15 Feb 2005
    5
    Medium

    CVE-2005-0426

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Solaris 8 and 9 allows remote attackers to cause a denial of service (panic) via "Heavy UDP Usage" that triggers a NULL dereference.

    Published: 15 Feb 2005
    5
    Medium

    CVE-2005-0427

    Last Modified: 16 Apr 2026

    The ebuild of Webmin before 1.170-r3 on Gentoo Linux includes the encrypted root password in the miniserv.users file when building a tbz2 of the webmin package, which allows remote attackers to obtain and possibly crack the encrypted password.

    Published: 15 Feb 2005
    7.5
    High

    CVE-2005-0431

    Last Modified: 16 Apr 2026

    Barracuda Spam Firewall 3.1.10 and earlier does not restrict the domains that white-listed domains can send mail to, which allows members of white-listed domains to use Barracuda as an open mail relay for spam.

    Published: 15 Feb 2005
    5
    Medium

    CVE-2005-0432

    Last Modified: 16 Apr 2026

    BEA WebLogic Server 7.0 Service Pack 5 and earlier, and 8.1 Service Pack 3 and earlier, generates different login exceptions that suggest why an authentication attempt fails, which makes it easier for remote attackers to guess passwords via brute force attacks.

    Published: 15 Feb 2005
    5
    Medium

    CVE-2005-0433

    Last Modified: 16 Apr 2026

    Php-Nuke 7.5 allows remote attackers to determine the full path of the web server via invalid or missing arguments to (1) db.php, (2) mainfile.php, (3) Downloads/index.php, or (4) Web_Links/index.php, which lists the path in a PHP error message.

    Published: 15 Feb 2005