CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2005-0435

    Last Modified: 16 Apr 2026

    awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to rawlog.

    Published: 15 Feb 2005
    7.5
    High

    CVE-2005-0436

    Last Modified: 16 Apr 2026

    Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the PluginMode parameter.

    Published: 15 Feb 2005
    7.5
    High

    CVE-2005-0440

    Last Modified: 16 Apr 2026

    ELOG before 2.5.7 allows remote attackers to bypass authentication and download a configuration file that contains a sensitive write password via a modified URL.

    Published: 15 Feb 2005
    5
    Medium

    CVE-2005-0442

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via the language parameter.

    Published: 15 Feb 2005
    4.3
    Medium

    CVE-2005-0445

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Open WebMail 2.x allows remote attackers to inject arbitrary HTML or web script via the domain name parameter (logindomain) in the login page.

    Published: 15 Feb 2005
    7.5
    High

    CVE-2005-0419

    Last Modified: 16 Apr 2026

    Multiple heap-based buffer overflows in 3Com 3CServer allow remote authenticated users to execute arbitrary code via long FTP commands, as demonstrated using the STAT command.

    Published: 15 Feb 2005
    5
    Medium

    CVE-2005-0428

    Last Modified: 16 Apr 2026

    The DNSPacket::expand method in dnspacket.cc in PowerDNS before 2.9.17 allows remote attackers to cause a denial of service by sending a random stream of bytes.

    Published: 15 Feb 2005
    4.3
    Medium

    CVE-2005-0434

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Php-Nuke 7.5 allow remote attackers to inject arbitrary HTML or web script via (1) the newdownloadshowdays parameter in a NewDownloads operation or (2) the newlinkshowdays parameter in a NewLinks operation.

    Published: 15 Feb 2005
    6.2
    Medium

    CVE-2005-0178

    Last Modified: 16 Apr 2026

    Race condition in the setsid function in Linux before 2.6.8.1 allows local users to cause a denial of service (crash) and possibly access portions of kernel memory, related to TTY changes, locking, and semaphores.

    Published: 15 Feb 2005
    5
    Medium

    CVE-2005-0176

    Last Modified: 16 Apr 2026

    The shmctl function in Linux 2.6.9 and earlier allows local users to unlock the memory of other processes, which could cause sensitive memory to be swapped to disk, which could allow it to be read by other users once it has been released.

    Published: 15 Feb 2005
    4.6
    Medium

    CVE-2005-0087

    Last Modified: 16 Apr 2026

    The alsa-lib package in Red Hat Linux 4 disables stack protection for the libasound.so library, which makes it easier for attackers to execute arbitrary code if there are other vulnerabilities in the library.

    Published: 15 Feb 2005
    7.8
    High

    CVE-2005-0177

    Last Modified: 16 Apr 2026

    nls_ascii.c in Linux before 2.6.8.1 uses an incorrect table size, which allows attackers to cause a denial of service (kernel crash) via a buffer overflow.

    Published: 15 Feb 2005
    2.1
    Low

    CVE-2005-0529

    Last Modified: 16 Apr 2026

    Linux kernel 2.6.10 and 2.6.11rc1-bk6 uses different size types for offset arguments to the proc_file_read and locks_read_proc functions, which leads to a heap-based buffer overflow when a signed comparison causes negative integers to be used in a positive context.

    Published: 15 Feb 2005
    2.1
    Low

    CVE-2005-0530

    Last Modified: 16 Apr 2026

    Signedness error in the copy_from_read_buf function in n_tty.c for Linux kernel 2.6.10 and 2.6.11rc1 allows local users to read kernel memory via a negative argument.

    Published: 15 Feb 2005
    2.1
    Low

    CVE-2005-0531

    Last Modified: 16 Apr 2026

    The atm_get_addr function in addr.c for Linux kernel 2.6.10 and 2.6.11 before 2.6.11-rc4 may allow local users to trigger a buffer overflow via negative arguments.

    Published: 15 Feb 2005
    5
    Medium

    CVE-2005-1260

    Last Modified: 16 Apr 2026

    bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb").

    Published: 15 Feb 2005
    6.8
    Medium

    CVE-2005-0412

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Spidean PostWrap allows remote attackers to inject arbitrary HTML and web script via the page parameter.

    Published: 14 Feb 2005
    7.5
    High

    CVE-2005-0416

    Last Modified: 16 Apr 2026

    The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allows remote attackers to execute arbitrary code via the AnimationHeaderBlock length field, which leads to a stack-based buffer overflow.

    Published: 14 Feb 2005
    5
    Medium

    CVE-2005-0229

    Last Modified: 16 Apr 2026

    CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote attackers to steal credit card information via a direct request to newfile.txt.

    Published: 14 Feb 2005
    7.5
    High

    CVE-2005-0413

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the fid in forum.php, (2) the member parameter in member.php, (3) the email parameter in forgot.php, or (4) the nbuser or nbpass parameters in include.php. NOTE: it was later reported that vector 2 exists in 3.0 and earlier.

    Published: 14 Feb 2005
    7.5
    High

    CVE-2005-0414

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in post.php for MercuryBoard 1.1.1 allows remote attackers to execute arbitrary SQL commands via a reply post action for index.php with (1) the t parameter or (2) the qu parameter.

    Published: 14 Feb 2005
    5.5
    Medium

    CVE-2005-0406

    Last Modified: 16 Apr 2026

    A design flaw in image processing software that modifies JPEG images might not modify the original EXIF thumbnail, which could lead to an information leak of potentially sensitive visual information that had been removed from the main JPEG image.

    Published: 14 Feb 2005
    9.8
    Critical

    CVE-2005-0408

    Last Modified: 16 Apr 2026

    CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to bypass authentication and gain privileges by calculating the MD5 checksum of the user name combined with the "boogaadeeboo" string, which is hard-coded in the $hidden_hash variable.

    Published: 14 Feb 2005
    6.4
    Medium

    CVE-2005-0409

    Last Modified: 16 Apr 2026

    CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit card data, and facilitates the exploitation of other vulnerabilities.

    Published: 14 Feb 2005
    5
    Medium

    CVE-2005-0410

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and earlier allows remote attackers to inject data via the fields of a CSV file.

    Published: 14 Feb 2005
    5
    Medium

    CVE-2005-0415

    Last Modified: 16 Apr 2026

    Multiple memory leaks in the MQL parser in Emdros before 1.1.22 allow remote attackers to cause a denial of service (memory consumption) via malformed MQL statements.

    Published: 14 Feb 2005
    10
    Critical

    CVE-2005-0417

    Last Modified: 16 Apr 2026

    Unknown "high risk" vulnerability in DB2 Universal Database 8.1 and earlier has unknown impact and attack vectors. NOTE: due to the delayed disclosure of details for this issue, this candidate may be SPLIT in the future. In addition, this may be a duplicate of other issues as reported by the vendor.

    Published: 14 Feb 2005
    4.6
    Medium

    CVE-2005-0444

    Last Modified: 16 Apr 2026

    VMware before 4.5.2.8848-r5 searches for gdk-pixbuf shared libraries using a path that includes the rrdharan world-writable temporary directory, which allows local users to execute arbitrary code.

    Published: 14 Feb 2005
    7.5
    High

    CVE-2005-0411

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and local users to include arbitrary PHP files via .. (dot dot) sequences in the load parameter.

    Published: 14 Feb 2005
    5
    Medium

    CVE-2005-0372

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in gftp before 2.0.18 for GTK+ allows remote malicious FTP servers to read arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.

    Published: 14 Feb 2005
    7.5
    High

    CVE-2005-0546

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Cyrus IMAPd before 2.2.11 may allow attackers to execute arbitrary code via (1) an off-by-one error in the imapd annotate extension, (2) an off-by-one error in "cached header handling," (3) a stack-based buffer overflow in fetchnews, or (4) a stack-based buffer overflow in imapd.

    Published: 14 Feb 2005
    7.8
    High

    CVE-2006-0453

    Last Modified: 16 Apr 2026

    The LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (crash) via a certain "bad BER sequence" that results in a free of uninitialized memory, as demonstrated using the ProtoVer LDAP test suite.

    Published: 14 Feb 2005
    4.3
    Medium

    CVE-2005-0374

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Bitboard 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via an [img] bbcode image tag with an event such as mouseover.

    Published: 13 Feb 2005
    5
    Medium

    CVE-2005-0382

    Last Modified: 16 Apr 2026

    Breed patch 1 and earlier allows remote attackers to cause a denial of service (application crash) via an empty UDP packet, which triggers a null dereference.

    Published: 13 Feb 2005
    7.5
    High

    CVE-2005-0377

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in imageview.php for SGallery 1.01 allows remote attackers to execute arbitrary SQL commands via the (1) idalbum or (2) idimage parameters.

    Published: 13 Feb 2005
    7.5
    High

    CVE-2005-0380

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in (1) print_category.php, (2) login.php, (3) setup.php, (4) ask_password.php, or (5) error.php in ZeroBoard 4.1pl5 and earlier allow remote attackers to execute arbitrary PHP code by modifying the dir parameter to reference a URL on a remote web server that contains the code.

    Published: 13 Feb 2005
    5
    Medium

    CVE-2005-0379

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in ZeroBoard 4.1pl5 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the _zb_path parameter to (1) _head.php or (2) outlogin.php, or the dir parameter to (3) write.php.

    Published: 13 Feb 2005
    5
    Medium

    CVE-2005-0375

    Last Modified: 16 Apr 2026

    imageview.php in SGallery 1.01 allows remote attackers to obtain sensitive information via an HTTP request with (1) idalbum and (2) idimage unset, which reveals the installation path in an error message for the sql_fetch_row function.

    Published: 13 Feb 2005
    4.3
    Medium

    CVE-2005-0378

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Horde 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to prefs.php or (2) url parameter to index.php.

    Published: 13 Feb 2005
    7.5
    High

    CVE-2005-0383

    Last Modified: 16 Apr 2026

    Trend Micro Control Manager 3.0 Enterprise Edition allows remote attackers to gain privileges via a replay attack of the encrypted username and password.

    Published: 13 Feb 2005
    5
    Medium

    CVE-2005-0446

    Last Modified: 16 Apr 2026

    Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qualified Domain Names (FQDN) in fqdncache.c or (2) IP addresses in ipcache.c, which trigger an assertion failure.

    Published: 13 Feb 2005
    5
    Medium

    CVE-2005-0430

    Last Modified: 16 Apr 2026

    The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash the server via a long infostring, possibly triggering a buffer overflow.

    Published: 12 Feb 2005
    5
    Medium

    CVE-2005-0366

    Last Modified: 16 Apr 2026

    The integrity check feature in OpenPGP, when handling a message that was encrypted using cipher feedback (CFB) mode, allows remote attackers to recover part of the plaintext via a chosen-ciphertext attack when the first 2 bytes of a message block are known, and an oracle or other mechanism is available to determine whether an integrity check failed.

    Published: 11 Feb 2005
    7.5
    High

    CVE-2005-0368

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in CMScore allow remote attackers to execute arbitrary SQL commands via the (1) EntryID or (2) searchterm parameter to index.php, or (3) username parameter to authenticate.php.

    Published: 11 Feb 2005
    5.3
    Medium

    CVE-2005-0369

    Last Modified: 16 Apr 2026

    Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a packet with a large (1) descriptor ID or (2) claim_id, which exceeds the boundaries of an array.

    Published: 11 Feb 2005
    4.6
    Medium

    CVE-2005-0073

    Last Modified: 16 Apr 2026

    Buffer overflow in queue.c in a support script for sympa 3.3.3, when running setuid, allows local users to execute arbitrary code.

    Published: 11 Feb 2005
    7.2
    High

    CVE-2005-0074

    Last Modified: 16 Apr 2026

    Buffer overflow in pcdsvgaview in xpcd 2.08 allows local users to execute arbitrary code.

    Published: 11 Feb 2005
    7.5
    High

    CVE-2005-0349

    Last Modified: 16 Apr 2026

    The production release of the UniversalAgent for UNIX in BrightStor ARCserve Backup 11.1 contains hard-coded credentials, which allows remote attackers to access the file system and possibly execute arbitrary commands.

    Published: 11 Feb 2005
    7.5
    High

    CVE-2005-0350

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in multiple F-Secure Anti-Virus and Internet Security products allows remote attackers to execute arbitrary code via a crafted ARJ archive.

    Published: 11 Feb 2005
    5
    Medium

    CVE-2005-0370

    Last Modified: 16 Apr 2026

    Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (network disconnection) via an empty UDP packet, which is not properly distinguished from the "no new packets" state of the associated socket.

    Published: 11 Feb 2005