CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2005-0014

    Last Modified: 16 Apr 2026

    Buffer overflow in ncplogin in ncpfs before 2.2.6 allows remote malicious NetWare servers to execute arbitrary code on the NetWare client.

    Published: 6 Feb 2005
    2.1
    Low

    CVE-2005-0017

    Last Modified: 16 Apr 2026

    The f2c translator in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.

    Published: 6 Feb 2005
    2.1
    Low

    CVE-2005-0018

    Last Modified: 16 Apr 2026

    The f2 shell script in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.

    Published: 6 Feb 2005
    5
    Medium

    CVE-2005-0133

    Last Modified: 16 Apr 2026

    ClamAV 0.80 and earlier allows remote attackers to cause a denial of service (clamd daemon crash) via a ZIP file with malformed headers.

    Published: 6 Feb 2005
    7.2
    High

    CVE-2005-0183

    Last Modified: 16 Apr 2026

    ftpfile in the Vacation plugin 0.15 and earlier for Squirrelmail allows local users to execute arbitrary commands via shell metacharacters in a command line argument.

    Published: 6 Feb 2005
    7.5
    High

    CVE-2005-0187

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the SetSkin function in AtHoc toolbar allows remote attackers to execute arbitrary code via a long skin name.

    Published: 6 Feb 2005
    6.1
    Medium

    CVE-2005-0197

    Last Modified: 16 Apr 2026

    Cisco IOS 12.1T, 12.2, 12.2T, 12.3 and 12.3T, with Multi Protocol Label Switching (MPLS) installed but disabled, allows remote attackers to cause a denial of service (device reload) via a crafted packet sent to the disabled interface.

    Published: 6 Feb 2005
    9.8
    Critical

    CVE-2005-0199

    Last Modified: 16 Apr 2026

    Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long MODE line that causes an incorrect length calculation, which leads to a buffer overflow.

    Published: 6 Feb 2005
    5
    Medium

    CVE-2005-0212

    Last Modified: 16 Apr 2026

    The Amp II engine as used by Gore: Ultimate Soldier 1.50 and earlier allows remote attackers to cause a denial of service (infinite loop) via a zero byte UDP packet.

    Published: 6 Feb 2005
    5
    Medium

    CVE-2005-0213

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in WinHKI 1.4d allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a zip file.

    Published: 6 Feb 2005
    5
    Medium

    CVE-2005-0214

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Simple PHP Blog (SPHPBlog) 0.3.7c allows remote attackers to read or create arbitrary files via a .. (dot dot) in the entry parameter.

    Published: 6 Feb 2005
    5
    Medium

    CVE-2005-0215

    Last Modified: 16 Apr 2026

    Mozilla 1.6 and possibly other versions allows remote attackers to cause a denial of service (application crash) via a XBM (X BitMap) file with a large (1) height or (2) width value.

    Published: 6 Feb 2005
    2.1
    Low

    CVE-2005-0225

    Last Modified: 16 Apr 2026

    firehol.sh in FireHOL before 1.224 creates temporary files with predictable file names, which could allow local users to overwrite arbitrary files via a symlink attack.

    Published: 6 Feb 2005
    5
    Medium

    CVE-2005-0218

    Last Modified: 16 Apr 2026

    ClamAV 0.80 and earlier allows remote attackers to bypass virus scanning via a base64 encoded image in a data: (RFC 2397) URL.

    Published: 6 Feb 2005
    5
    Medium

    CVE-2005-0220

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in login.php in Gallery 1.4.4-pl2 allows remote attackers to inject arbitrary web script or HTML via the username field.

    Published: 6 Feb 2005
    5
    Medium

    CVE-2005-0222

    Last Modified: 16 Apr 2026

    main.php in Gallery 2.0 Alpha allows remote attackers to gain sensitive information by changing the value of g2_subView parameter, which reveals the path in an error message.

    Published: 6 Feb 2005
    5
    Medium

    CVE-2005-0223

    Last Modified: 16 Apr 2026

    The Software Development Kit (SDK) and Run Time Environment (RTE) 1.4.1 and 1.4.2 for Tru64 UNIX allows remote attackers to cause a denial of service (Java Virtual Machine hang) via object deserialization.

    Published: 6 Feb 2005
    Unknown

    CVE-2005-0228

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-1388. Reason: This candidate is a duplicate of CVE-2004-1388. Notes: All CVE users should reference CVE-2004-1388 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 Feb 2005
    10
    Critical

    CVE-2005-0194

    Last Modified: 16 Apr 2026

    Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.

    Published: 6 Feb 2005
    7.5
    High

    CVE-2005-0200

    Last Modified: 16 Apr 2026

    TikiWiki before 1.8.5 does not properly validate files that have been uploaded to the temp directory, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2004-1386.

    Published: 6 Feb 2005
    4.3
    Medium

    CVE-2005-0216

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in formmail.php in Woltlab Burning Board Lite 1.0.0, 1.0.1e, and possibly other versions, allows remote attackers to inject arbitrary web script and HTML via the userid parameter.

    Published: 6 Feb 2005
    7.5
    High

    CVE-2005-0100

    Last Modified: 16 Apr 2026

    Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.

    Published: 6 Feb 2005
    2.1
    Low

    CVE-2005-0977

    Last Modified: 16 Apr 2026

    The shmem_nopage function in shmem.c for the tmpfs driver in Linux kernel 2.6 does not properly verify the address argument, which allows local users to cause a denial of service (kernel crash) via an invalid address.

    Published: 5 Feb 2005
    7.5
    High

    CVE-2005-2801

    Last Modified: 16 Apr 2026

    xattr.c in the ext2 and ext3 file system code for Linux kernel 2.6 does not properly compare the name_index fields when sharing xattr blocks, which could prevent default ACLs from being applied.

    Published: 5 Feb 2005
    7.5
    High

    CVE-2005-0226

    Last Modified: 16 Apr 2026

    Format string vulnerability in the Log_Resolver function in log.c for ngIRCd 0.8.2 and earlier, when compiled with IDENT, logging to SYSLOG, and with DEBUG enabled, allows remote attackers to execute arbitrary code.

    Published: 3 Feb 2005
    7.5
    High

    CVE-2005-0089

    Last Modified: 16 Apr 2026

    The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instance method to register an object without a _dispatch method, allows remote attackers to read or modify globals of the associated module, and possibly execute arbitrary code, via dotted attributes.

    Published: 3 Feb 2005
    7.5
    High

    CVE-2005-0152

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via "URL manipulation."

    Published: 2 Feb 2005
    7.5
    High

    CVE-2005-0397

    Last Modified: 16 Apr 2026

    Format string vulnerability in the SetImageInfo function in image.c for ImageMagick before 6.0.2.5 may allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a filename argument to convert, which may be called by other web applications.

    Published: 2 Feb 2005
    7.5
    High

    CVE-2005-0101

    Last Modified: 16 Apr 2026

    Buffer overflow in the socket_getline function in Newspost 2.1.1 and earlier allows remote malicious NNTP servers to execute arbitrary code via a long string without a newline character.

    Published: 1 Feb 2005
    2.1
    Low

    CVE-2005-0156

    Last Modified: 16 Apr 2026

    Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.

    Published: 1 Feb 2005
    6.5
    Medium

    CVE-2005-0247

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in gram.y for PostgreSQL 8.0.1 and earlier may allow attackers to execute arbitrary code via (1) a large number of variables in a SQL statement being handled by the read_sql_construct function, (2) a large number of INTO variables in a SELECT statement being handled by the make_select_stmt function, (3) a large number of arbitrary variables in a SELECT statement being handled by the make_select_stmt function, and (4) a large number of INTO variables in a FETCH statement being handled by the make_fetch_stmt function, a different set of vulnerabilities than CVE-2005-0245.

    Published: 1 Feb 2005
    4.6
    Medium

    CVE-2005-0155

    Last Modified: 16 Apr 2026

    The PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to create arbitrary files via the PERLIO_DEBUG variable.

    Published: 1 Feb 2005
    5
    Medium

    CVE-2005-0224

    Last Modified: 16 Apr 2026

    Unknown vulnerability in HP-UX B.11.04 running Virtualvault 4.5 through 4.7, when running the TGA daemon, allows remote attackers to cause a denial of service via certain network traffic.

    Published: 31 Jan 2005
    5
    Medium

    CVE-2005-0174

    Last Modified: 16 Apr 2026

    Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.

    Published: 31 Jan 2005
    5
    Medium

    CVE-2005-0241

    Last Modified: 16 Apr 2026

    The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size.

    Published: 31 Jan 2005
    5
    Medium

    CVE-2005-0175

    Last Modified: 16 Apr 2026

    Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.

    Published: 31 Jan 2005
    2.1
    Low

    CVE-2005-0201

    Last Modified: 16 Apr 2026

    D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another user's per-user session bus via that socket.

    Published: 31 Jan 2005
    7.5
    High

    CVE-2005-0337

    Last Modified: 16 Apr 2026

    Postfix 2.1.3, when /proc/net/if_inet6 is not available and permit_mx_backup is enabled in smtpd_recipient_restrictions, allows remote attackers to bypass e-mail restrictions and perform mail relaying by sending mail to an IPv6 hostname.

    Published: 31 Jan 2005
    4.9
    Medium

    CVE-2005-0210

    Last Modified: 16 Apr 2026

    Netfilter in the Linux kernel 2.6.8.1 allows local users to cause a denial of service (memory consumption) via certain packet fragments that are reassembled twice, which causes a data structure to be allocated twice.

    Published: 30 Jan 2005
    7.2
    High

    CVE-2005-0013

    Last Modified: 16 Apr 2026

    nwclient.c in ncpfs before 2.2.6 does not drop root privileges before executing utilities using the NetWare client functions, which allows local users to gain privileges.

    Published: 30 Jan 2005
    5
    Medium

    CVE-2005-0071

    Last Modified: 16 Apr 2026

    vdr before 1.2.6 does not securely create files, which allows attackers to overwrite arbitrary files.

    Published: 29 Jan 2005
    7.2
    High

    CVE-2005-0125

    Last Modified: 16 Apr 2026

    The "at" commands on Mac OS X 10.3.7 and earlier do not properly drop privileges, which allows local users to (1) delete arbitrary files via atrm, (2) execute arbitrary programs via the -f argument to batch, or (3) read arbitrary files via the -f argument to batch, which generates a job file that is readable by the local user.

    Published: 29 Jan 2005
    5
    Medium

    CVE-2005-0148

    Last Modified: 16 Apr 2026

    Thunderbird before 0.9, when running on Windows systems, uses the default handler when processing javascript: links, which invokes Internet Explorer and may expose the Thunderbird user to vulnerabilities in the version of Internet Explorer that is installed on the user's system. NOTE: since the invocation between multiple products is a common practice, and the vulnerabilities inherent in multi-product interactions are not easily enumerable, this issue might be REJECTED in the future.

    Published: 29 Jan 2005
    7.5
    High

    CVE-2005-0015

    Last Modified: 16 Apr 2026

    diatheke.pl in Sword 1.5.7a allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.

    Published: 29 Jan 2005
    5
    Medium

    CVE-2005-0033

    Last Modified: 16 Apr 2026

    Buffer overflow in the code for recursion and glue fetching in BIND 8.4.4 and 8.4.5 allows remote attackers to cause a denial of service (crash) via queries that trigger the overflow in the q_usedns array that tracks nameservers and addresses.

    Published: 29 Jan 2005
    4.3
    Medium

    CVE-2005-0034

    Last Modified: 16 Apr 2026

    An "incorrect assumption" in the authvalidated validator function in BIND 9.3.0, when DNSSEC is enabled, allows remote attackers to cause a denial of service (named server exit) via crafted DNS packets that cause an internal consistency test (self-check) to fail.

    Published: 29 Jan 2005
    7.5
    High

    CVE-2005-0126

    Last Modified: 16 Apr 2026

    ColorSync on Mac OS X 10.3.7 and 10.3.8 allows attackers to execute arbitrary code via malformed ICC color profiles that modify the heap.

    Published: 29 Jan 2005
    5
    Medium

    CVE-2005-0127

    Last Modified: 16 Apr 2026

    Mail in Mac OS X 10.3.7, when generating a Message-ID header, generates a GUUID that includes information that identifies the Ethernet hardware being used, which allows remote attackers to link mail messages to a particular machine.

    Published: 29 Jan 2005
    7.5
    High

    CVE-2005-0140

    Last Modified: 16 Apr 2026

    Buffer overflow in PeID allows attackers to execute arbitrary code via a PE file with an Import Address Table containing a long import library name.

    Published: 29 Jan 2005
    5
    Medium

    CVE-2005-0150

    Last Modified: 16 Apr 2026

    Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code.

    Published: 29 Jan 2005