CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2005-0371

    Last Modified: 16 Apr 2026

    Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (freeze) via a large number of player connections that do not send any data.

    Published: 11 Feb 2005
    2.1
    Low

    CVE-2005-0114

    Last Modified: 16 Apr 2026

    vsdatant.sys in Zone Lab ZoneAlarm before 5.5.062.011, ZoneAlarm Wireless before 5.5.080.000, Check Point Integrity Client 4.x before 4.5.122.000 and 5.x before 5.1.556.166 do not properly verify that the ServerPortName argument to the NtConnectPort function is a valid memory address, which allows local users to cause a denial of service (system crash) when ZoneAlarm attempts to dereference an invalid pointer.

    Published: 11 Feb 2005
    4.3
    Medium

    CVE-2005-0270

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to inject arbitrary web script or HTML via the (1) si parameter to showcat.php, (2) cat or (3) page parameter to showproduct.php, or (4) report parameter to reportproduct.php.

    Published: 10 Feb 2005
    4.3
    Medium

    CVE-2005-0303

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_supportError.asp or (2) comersus_backofficelite_supportError.asp in BackOffice Lite 6.0 and 6.01 allow remote attackers to inject arbitrary web script or HTML via the error parameter.

    Published: 10 Feb 2005
    7.5
    High

    CVE-2005-0305

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in users.php in Siteman 1.1.10 and earlier allows remote attackers to add arbitrary users and gain privileges via the line parameter in a docreate operation.

    Published: 10 Feb 2005
    7.2
    High

    CVE-2005-0322

    Last Modified: 16 Apr 2026

    MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 and Mail Server 7.6.4r with Icewarp Mail Server 5.3.2 uses weak encryption in the (1) users.cfg, (2) settings.cfg, (3) users.dat or (4) user.dat files, which allows local users to extract the passwords.

    Published: 10 Feb 2005
    7.5
    High

    CVE-2005-0338

    Last Modified: 16 Apr 2026

    Buffer overflow in Savant Web Server 3.1 allows remote attackers to execute arbitrary code via a long HTTP request.

    Published: 10 Feb 2005
    10
    Critical

    CVE-2005-0260

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the Discovery Service for BrightStor ARCserve Backup 11.1 and earlier allows remote attackers to execute arbitrary code via a long packet to UDP port 41524, which is not properly handled in a recvfrom call.

    Published: 10 Feb 2005
    7.2
    High

    CVE-2005-0262

    Last Modified: 16 Apr 2026

    Buffer overflow in ipl_varyon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -d argument.

    Published: 10 Feb 2005
    5
    Medium

    CVE-2005-0277

    Last Modified: 16 Apr 2026

    Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via (1) a long username in the USER command or (2) an FTP command that contains a long argument, such as cd, send, or ls.

    Published: 10 Feb 2005
    5
    Medium

    CVE-2005-0278

    Last Modified: 16 Apr 2026

    The FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to gain sensitive information via a cd command that contains an MS-DOS device name, which reveals the installation path in an error message.

    Published: 10 Feb 2005
    5
    Medium

    CVE-2005-0298

    Last Modified: 16 Apr 2026

    The DIRECTORY objects in Oracle 8i through Oracle 10g contain the location of a specific operating system directory, which allows users with read privileges to a DIRECTORY object to obtain sensitive information.

    Published: 10 Feb 2005
    7.5
    High

    CVE-2005-0301

    Last Modified: 16 Apr 2026

    comersus_backoffice_install10.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to bypass authentication and gain privileges via a direct request to the program.

    Published: 10 Feb 2005
    5
    Medium

    CVE-2005-0310

    Last Modified: 16 Apr 2026

    Exponent 0.95 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) search.info.php, (2) permissions.info.php, (3) security.info.php, (4) formcontrol.php, or (5) file_modules.php, which reveals the path in an error message because the pathos_core_version variable is undefined.

    Published: 10 Feb 2005
    4.3
    Medium

    CVE-2005-0323

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Infinite Mobile Delivery Webmail 2.6 allows remote attackers to inject arbitrary web script or HTML via the URL.

    Published: 10 Feb 2005
    5
    Medium

    CVE-2005-0328

    Last Modified: 16 Apr 2026

    Zyxel P310, P314, P324 and Netgear RT311, RT314 running the latest firmware, allows remote attackers on the WAN to obtain the IP address of the LAN side interface by pinging a valid LAN IP address, which generates an ARP reply from the WAN address side that maps the LAN IP address to the WAN's MAC address.

    Published: 10 Feb 2005
    2.1
    Low

    CVE-2005-0330

    Last Modified: 16 Apr 2026

    Buffer overflow in Painkiller 1.35 and earlier, and possibly other versions before 1.61, allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via a long cd-key hash.

    Published: 10 Feb 2005
    2.6
    Low

    CVE-2005-0331

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in WinRAR 3.42 and earlier, when the user clicks on the ZIP file to extract it, allows remote attackers to create arbitrary files via a ... (triple dot) in the filename of the ZIP file.

    Published: 10 Feb 2005
    5.1
    Medium

    CVE-2005-0347

    Last Modified: 16 Apr 2026

    Integer overflow in RealArcade 1.2.0.994 and earlier allows remote attackers to execute arbitrary code via an RGS file with an invalid size string for the GUID and game name, which leads to a buffer overflow.

    Published: 10 Feb 2005
    5
    Medium

    CVE-2005-0293

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in minis.php in Minis 0.2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the month parameter.

    Published: 10 Feb 2005
    7.2
    High

    CVE-2005-0076

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the XView library 3.2 may allow local users to execute arbitrary code via setuid applications that use the library.

    Published: 10 Feb 2005
    5.1
    Medium

    CVE-2005-0230

    Last Modified: 16 Apr 2026

    Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."

    Published: 10 Feb 2005
    7.5
    High

    CVE-2005-0267

    Last Modified: 16 Apr 2026

    index.php in FlatNuke 2.5.1 allows remote attackers to create an administrator account via carriage returns and #10 in the url_avatar field, which is interpreted as a sensitive directive.

    Published: 10 Feb 2005
    2.1
    Low

    CVE-2005-0261

    Last Modified: 16 Apr 2026

    lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.

    Published: 10 Feb 2005
    7.2
    High

    CVE-2005-0263

    Last Modified: 16 Apr 2026

    Buffer overflow in netpmon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -O argument.

    Published: 10 Feb 2005
    4.3
    Medium

    CVE-2005-0264

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) expand or (2) order parameter.

    Published: 10 Feb 2005
    7.5
    High

    CVE-2005-0265

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to execute arbitrary SQL commands via the (1) parent or (2) sortposted parameter.

    Published: 10 Feb 2005
    7.5
    High

    CVE-2005-0272

    Last Modified: 16 Apr 2026

    ReviewPost PHP Pro before 2.84 allows remote attackers to upload and execute arbitrary PHP files by posting a review file with multiple extensions, which bypasses the intended restrictions.

    Published: 10 Feb 2005
    7.5
    High

    CVE-2005-0273

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) ppuser parameter.

    Published: 10 Feb 2005
    5
    Medium

    CVE-2005-0275

    Last Modified: 16 Apr 2026

    TFTP in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) via a GET request containing an MS-DOS device name.

    Published: 10 Feb 2005
    5
    Medium

    CVE-2005-0279

    Last Modified: 16 Apr 2026

    Soldner Secret Wars 30830 and earlier does not properly handle the "message too long" socket error, which allows remote attackers to cause a denial of service (socket termination) via a long UDP packet.

    Published: 10 Feb 2005
    4.3
    Medium

    CVE-2005-0281

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the web interface in Soldner Secret Wars 30830 allows remote attackers to inject arbitrary web script or HTML via a user message, which is not filtered or quoted when the administrator views the server logs.

    Published: 10 Feb 2005
    7.5
    High

    CVE-2005-0282

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in member.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the uid parameter.

    Published: 10 Feb 2005
    5
    Medium

    CVE-2005-0289

    Last Modified: 16 Apr 2026

    Apple AirPort Express prior to 6.1.1 and Extreme prior to 5.5.1, configured as a Wireless Data Service (WDS), allows remote attackers to cause a denial of service (device freeze) by connecting to UDP port 161 and before link-state change occurs.

    Published: 10 Feb 2005
    5
    Medium

    CVE-2005-0304

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in DivX Player 2.6 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a filename in a ZIP file for a skin.

    Published: 10 Feb 2005
    5
    Medium

    CVE-2005-0286

    Last Modified: 16 Apr 2026

    eMotion MediaPartner Web Server 5.0 and 5.1 allows remote attackers to obtain sensitive information via an HTTP request for a .bhtml file that contains a (1) . (dot) or (2) + (plus sign) at the end, which returns the source code for that file.

    Published: 10 Feb 2005
    5
    Medium

    CVE-2005-0299

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in GForge 3.3 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the (1) dir parameter to controller.php or (2) dir_name parameter to controlleroo.php.

    Published: 10 Feb 2005
    7.5
    High

    CVE-2005-0302

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in default.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to execute arbitrary SQL commands via the referer field in the HTTP header.

    Published: 10 Feb 2005
    4.6
    Medium

    CVE-2005-0311

    Last Modified: 16 Apr 2026

    Ingate Firewall 4.1.3 and earlier does not terminate the PPTP session for an active user when the administrator disables that user from a resource, which could allow remote authenticated users to retain unauthorized access to resources.

    Published: 10 Feb 2005
    5
    Medium

    CVE-2005-0364

    Last Modified: 16 Apr 2026

    Unknown vulnerability in BIND 9.2.0 in HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to cause a denial of service.

    Published: 10 Feb 2005
    5
    Medium

    CVE-2005-0324

    Last Modified: 16 Apr 2026

    Infinite Mobile Delivery Webmail 2.6 allows remote attackers to gain sensitive information via an HTTP request that contains invalid characters for a Windows foldername, which reveals the path in an error message.

    Published: 10 Feb 2005
    5
    Medium

    CVE-2005-0325

    Last Modified: 16 Apr 2026

    Xpand Rally 1.0.0.0 allows remote attackers or remote malicious game servers to cause a denial of service (application crash) via a packet with large values that are not properly handled in certain malloc or memcpy operations.

    Published: 10 Feb 2005
    5
    Medium

    CVE-2005-0326

    Last Modified: 16 Apr 2026

    pafiledb.php in PaFileDB 3.1 allows remote attackers to gain sensitive information via an invalid or missing action parameter, which reveals the path in an error message when it cannot include a login.php script.

    Published: 10 Feb 2005
    7.5
    High

    CVE-2005-0327

    Last Modified: 16 Apr 2026

    pafiledb.php in Pafiledb 3.1 may allow remote attackers to execute arbitrary PHP code via a modified action parameter that is used in an include statement for login.php.

    Published: 10 Feb 2005
    5
    Medium

    CVE-2005-0333

    Last Modified: 16 Apr 2026

    LANChat Pro Revival 1.666c allows remote attackers to cause a denial of service (application crash) via a malformed UDP packet.

    Published: 10 Feb 2005
    5
    Medium

    CVE-2005-0334

    Last Modified: 16 Apr 2026

    Linksys PSUS4 running firmware 6032 allows remote attackers to cause a denial of service (device crash) via an HTTP POST request containing an unknown parameter without a value.

    Published: 10 Feb 2005
    5
    Medium

    CVE-2005-0335

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in EMotion MediaPartner Web Server 5.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

    Published: 10 Feb 2005
    4.3
    Medium

    CVE-2005-0336

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in EMotion MediaPartner Web Server 5.0 allows remote attackers to inject arbitrary HTML or web script, as demonstrated using a URL containing .. sequences and HTML, which results in a directory browsing page that does not properly filter the HTML.

    Published: 10 Feb 2005
    5
    Medium

    CVE-2005-0340

    Last Modified: 16 Apr 2026

    Integer signedness error in Apple File Service (AFP Server) allows remote attackers to cause a denial of service (application crash) via a negative UAM string length in a FPLoginExt packet.

    Published: 10 Feb 2005
    4.3
    Medium

    CVE-2005-0341

    Last Modified: 16 Apr 2026

    Apple Safari 1.2.4 does not obey the Content-type field in the HTTP header and renders text as HTML, which allows remote attackers to inject arbitrary web script or HTML and perform cross-site scripting (XSS) attacks.

    Published: 10 Feb 2005