CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2005-0342

    Last Modified: 16 Apr 2026

    The Finder in Mac OS X and earlier allows local users to overwrite arbitrary files and gain privileges by creating a hard link from the .DS_Store file to an arbitrary file.

    Published: 10 Feb 2005
    7.5
    High

    CVE-2005-0343

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in PerlDesk 1.x allows remote attackers to inject arbitrary SQL commands via the view parameter.

    Published: 10 Feb 2005
    5
    Medium

    CVE-2005-0344

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in 602LAN SUITE 2004.0.04.1221 allows remote authenticated users to upload and execute arbitrary files via a .. (dot dot) in the filename parameter.

    Published: 10 Feb 2005
    5
    Medium

    CVE-2005-0345

    Last Modified: 16 Apr 2026

    viewthread.php in php-fusion 4.x does not check the (1) forum_id or (2) forum_cat parameters, which allows remote attackers to view protected forums via the thread_id parameter.

    Published: 10 Feb 2005
    10
    Critical

    CVE-2005-0339

    Last Modified: 16 Apr 2026

    Buffer overflow in Foxmail 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long MAIL FROM command.

    Published: 10 Feb 2005
    2.6
    Low

    CVE-2005-0348

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in RealArcade 1.2.0.994 allows remote attackers to delete arbitrary files via an RGP file with a .. (dot dot) in the FILENAME tag.

    Published: 10 Feb 2005
    9.8
    Critical

    CVE-2005-0269

    Last Modified: 16 Apr 2026

    The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary files via file extensions that include uppercase letters.

    Published: 10 Feb 2005
    5
    Medium

    CVE-2005-0276

    Last Modified: 16 Apr 2026

    Multiple format string vulnerabilities in the FTP service in 3Com 3CDaemon 2.0 revision 10 allow remote attackers to cause a denial of service (application crash) via format string specifiers in (1) the username, (2) cd, (3) delete, (4) rename, (5) rmdir, (6) literal, (7) stat, or (8) CWD commands.

    Published: 10 Feb 2005
    4.6
    Medium

    CVE-2005-0285

    Last Modified: 16 Apr 2026

    Webseries Payment Application does not properly restrict privileged operations, which allows remote authenticated users to gain privileges by directly accessing certain URLs.

    Published: 10 Feb 2005
    2.1
    Low

    CVE-2005-0321

    Last Modified: 16 Apr 2026

    MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allows remote authenticated users to gain sensitive information via an HTTP request to (1) calendar_d.html, (2) calendar_m.html, (3) calendar_w.html, or (4) calendar_y.html, which reveal the installation path.

    Published: 10 Feb 2005
    2.6
    Low

    CVE-2005-0329

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in ZipGenius 5.5 and earlier allows remote attackers to create and possibly modify arbitrary files via a ZIP file with a file whose name includes .. (dot dot) sequences.

    Published: 10 Feb 2005
    7.5
    High

    CVE-2005-0332

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in DeskNow Mail and Collaboration Server 2.5.12 allows remote attackers to (1) upload and possibly execute files outside the directory via the AttachmentsKey parameter to attachment.do, as demonstrated using JSP pages, or (2) delete arbitrary files via the select_file parameter to file.do.

    Published: 10 Feb 2005
    2.1
    Low

    CVE-2005-0346

    Last Modified: 16 Apr 2026

    SafeNet SoftRemote VPN Client stores the VPN password (pre-shared key) in cleartext in memory of the IreIKE.exe process, which allows local users to gain sensitive information if they have access to that process.

    Published: 10 Feb 2005
    7.5
    High

    CVE-2005-0088

    Last Modified: 16 Apr 2026

    The publisher handler for mod_python 2.7.8 and earlier allows remote attackers to obtain access to restricted objects via a crafted URL.

    Published: 10 Feb 2005
    4.6
    Medium

    CVE-2005-0367

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in ArGoSoft Mail Server 1.8.7.3 allow remote authenticated users to read, delete, or upload arbitrary files via a .. (dot dot) in (1) the filename of an e-mail attachment, (2) the _msgatt.rec file, (3) and the /msg, /delete, /folderadd, and /folderdelete operations for the Folder parameter.

    Published: 9 Feb 2005
    4.6
    Medium

    CVE-2005-0362

    Last Modified: 16 Apr 2026

    awstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "pluginmode", (2) "loadplugin", or (3) "noloadplugin" parameters.

    Published: 9 Feb 2005
    5
    Medium

    CVE-2005-0202

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the true_path function in private.py for Mailman 2.1.5 and earlier allows remote attackers to read arbitrary files via ".../....///" sequences, which are not properly cleansed by regular expressions that are intended to remove "../" and "./" sequences.

    Published: 9 Feb 2005
    4.3
    Medium

    CVE-2005-0049

    Last Modified: 16 Apr 2026

    Windows SharePoint Services and SharePoint Team Services for Windows Server 2003 does not properly validate an HTTP redirection query, which allows remote attackers to inject arbitrary HTML and web script via a cross-site scripting (XSS) attack, or to spoof the web cache.

    Published: 8 Feb 2005
    7.5
    High

    CVE-2005-0053

    Last Modified: 16 Apr 2026

    Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."

    Published: 8 Feb 2005
    7.5
    High

    CVE-2004-0848

    Last Modified: 16 Apr 2026

    Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames.

    Published: 8 Feb 2005
    7.5
    High

    CVE-2005-0045

    Last Modified: 16 Apr 2026

    The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code via Transaction responses containing (1) Trans or (2) Trans2 commands, aka the "Server Message Block Vulnerability," and as demonstrated using Trans2 FIND_FIRST2 responses with large file name length fields.

    Published: 8 Feb 2005
    7.5
    High

    CVE-2005-0051

    Last Modified: 16 Apr 2026

    The Server service (srvsvc.dll) in Windows XP SP1 and SP2 allows remote attackers to obtain sensitive information (users who are accessing resources) via an anonymous logon using a named pipe, which is not properly authenticated, aka the "Named Pipe Vulnerability."

    Published: 8 Feb 2005
    7.5
    High

    CVE-2005-0057

    Last Modified: 16 Apr 2026

    The Hyperlink Object Library for Windows 98, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a crafted link that triggers an "unchecked buffer" in the library, possibly due to a buffer overflow.

    Published: 8 Feb 2005
    7.5
    High

    CVE-2005-0249

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header.

    Published: 8 Feb 2005
    7.2
    High

    CVE-2005-0250

    Last Modified: 16 Apr 2026

    Format string vulnerability in auditselect on IBM AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via format string specifiers in a command line argument.

    Published: 8 Feb 2005
    7.2
    High

    CVE-2005-0047

    Last Modified: 16 Apr 2026

    Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability."

    Published: 8 Feb 2005
    5.1
    Medium

    CVE-2005-0054

    Last Modified: 16 Apr 2026

    Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."

    Published: 8 Feb 2005
    7.5
    High

    CVE-2005-0055

    Last Modified: 16 Apr 2026

    Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."

    Published: 8 Feb 2005
    7.5
    High

    CVE-2005-0248

    Last Modified: 16 Apr 2026

    The Solaris Management Console (SMC) GUI for Solaris 8 and 9, when creating user accounts that are configured for password aging, creates the accounts with a blank password, which allows remote or local attackers to break into those accounts.

    Published: 8 Feb 2005
    7.5
    High

    CVE-2005-0044

    Last Modified: 16 Apr 2026

    The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the "Input Validation Vulnerability."

    Published: 8 Feb 2005
    10
    Critical

    CVE-2005-0050

    Last Modified: 16 Apr 2026

    The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, aka the "License Logging Service Vulnerability."

    Published: 8 Feb 2005
    5.1
    Medium

    CVE-2005-0056

    Last Modified: 16 Apr 2026

    Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."

    Published: 8 Feb 2005
    6.9
    Medium

    CVE-2005-0767

    Last Modified: 16 Apr 2026

    Race condition in the Radeon DRI driver for Linux kernel 2.6.8.1 allows local users with DRI privileges to execute arbitrary code as root.

    Published: 8 Feb 2005
    5
    Medium

    CVE-2005-0235

    Last Modified: 16 Apr 2026

    The International Domain Name (IDN) support in Opera 7.54 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.

    Published: 7 Feb 2005
    5
    Medium

    CVE-2005-0236

    Last Modified: 16 Apr 2026

    The International Domain Name (IDN) support in Omniweb 5 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.

    Published: 7 Feb 2005
    5
    Medium

    CVE-2005-0238

    Last Modified: 16 Apr 2026

    The International Domain Name (IDN) support in Epiphany allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.

    Published: 7 Feb 2005
    7.5
    High

    CVE-2005-0239

    Last Modified: 16 Apr 2026

    viewcert.php in the S/MIME plugin 0.4 and 0.5 for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacters in the cert parameter.

    Published: 7 Feb 2005
    7.2
    High

    CVE-2005-0240

    Last Modified: 16 Apr 2026

    Format string vulnerability in chdev on IBM AIX 5.2 allows local users to execute arbitrary code via format string specifiers in a command line argument, which is not properly handled when printing an error message.

    Published: 7 Feb 2005
    7.2
    High

    CVE-2004-1131

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the enable command for SCO OpenServer 5.0.6 and 5.0.7 allow local users to execute arbitrary code via long command line arguments.

    Published: 7 Feb 2005
    5
    Medium

    CVE-2005-0234

    Last Modified: 16 Apr 2026

    The International Domain Name (IDN) support in Safari 1.2.5 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.

    Published: 7 Feb 2005
    5
    Medium

    CVE-2005-0237

    Last Modified: 16 Apr 2026

    The International Domain Name (IDN) support in Konqueror 3.2.1 on KDE 3.2.1 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.

    Published: 7 Feb 2005
    7.5
    High

    CVE-2005-0233

    Last Modified: 16 Apr 2026

    The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.

    Published: 7 Feb 2005
    2.6
    Low

    CVE-2005-0231

    Last Modified: 16 Apr 2026

    Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."

    Published: 7 Feb 2005
    2.6
    Low

    CVE-2005-0232

    Last Modified: 16 Apr 2026

    Firefox 1.0 allows remote attackers to modify Boolean configuration parameters for the about:config site by using a plugin such as Flash, and the -moz-opacity filter, to display the about:config site then cause the user to double-click at a certain screen position, aka "Fireflashing."

    Published: 7 Feb 2005
    2.1
    Low

    CVE-2005-0184

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in ftpfile in the Vacation plugin 0.15 and earlier for Squirrelmail allows local users to read arbitrary files via a .. (dot dot) in a get request.

    Published: 6 Feb 2005
    7.5
    High

    CVE-2005-0185

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in NodeManager Professional 2.00 allows remote attackers to execute arbitrary commands via a LinkDown-Trap packet that contains a long OCTET-STRING in the Trap variable-bindings field.

    Published: 6 Feb 2005
    5
    Medium

    CVE-2005-0195

    Last Modified: 16 Apr 2026

    Cisco IOS 12.0S through 12.3YH allows remote attackers to cause a denial of service (device restart) via a crafted IPv6 packet.

    Published: 6 Feb 2005
    5
    Medium

    CVE-2005-0196

    Last Modified: 16 Apr 2026

    Cisco IOS 12.0 through 12.3YL, with BGP enabled and running the bgp log-neighbor-changes command, allows remote attackers to cause a denial of service (device reload) via a malformed BGP packet.

    Published: 6 Feb 2005
    7.5
    High

    CVE-2005-0217

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in Invision Community Blog allows remote attackers to execute arbitrary SQL commands via the eid parameter.

    Published: 6 Feb 2005
    4.3
    Medium

    CVE-2005-0219

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Gallery 1.3.4-pl1 allow remote attackers to inject arbitrary web script or HTML via (1) the index field in add_comment.php, (2) set_albumName, (3) slide_index, (4) slide_full, (5) slide_loop, (6) slide_pause, (7) slide_dir fields in slideshow_low.php, or (8) username field in search.php.

    Published: 6 Feb 2005