CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2005-0079

    Last Modified: 16 Apr 2026

    Buffer overflow in xtrlock 2.0 allows local users to cause a denial of service (application crash) and hijack the desktop session.

    Published: 29 Jan 2005
    6.8
    Medium

    CVE-2008-3432

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the mch_expand_wildcards function in os_unix.c in Vim 6.2 and 6.3 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames, as demonstrated by the netrw.v3 test case.

    Published: 29 Jan 2005
    7.5
    High

    CVE-2005-0316

    Last Modified: 16 Apr 2026

    WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which could allow remote attackers to bypass intended access restrictions.

    Published: 28 Jan 2005
    4.3
    Medium

    CVE-2005-0317

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in useredit_account.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the user parameter.

    Published: 28 Jan 2005
    2.1
    Low

    CVE-2005-0318

    Last Modified: 16 Apr 2026

    useredit_account.wdm in Alt-N WebAdmin 3.0.4 does not properly validate account edits by the logged in user, which allows remote authenticated users to edit other users' account information via a modified user parameter.

    Published: 28 Jan 2005
    4.3
    Medium

    CVE-2005-0319

    Last Modified: 16 Apr 2026

    Direct remote injection vulnerability in modalfram.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to load external webpages that appear to come from the WebAdmin server, which allows remote attackers to inject arbitrary HTML or web script to facilitate cross-site scripting (XSS) and phishing attacks.

    Published: 28 Jan 2005
    5
    Medium

    CVE-2005-0320

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to login.html, (2) accountid parameter to accountsettings_add.html, or the (3) note, (4) title, and (5) location fields to calendar.html.

    Published: 28 Jan 2005
    7.5
    High

    CVE-2005-0211

    Last Modified: 16 Apr 2026

    Buffer overflow in wccp.c in Squid 2.5 before 2.5.STABLE7 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long WCCP packet, which is processed by a recvfrom function call that uses an incorrect length parameter.

    Published: 28 Jan 2005
    7.2
    High

    CVE-2005-0839

    Last Modified: 16 Apr 2026

    Linux kernel 2.6 before 2.6.11 does not restrict access to the N_MOUSE line discipline for a TTY, which allows local users to gain privileges by injecting mouse or keyboard events into other user sessions.

    Published: 28 Jan 2005
    7.5
    High

    CVE-2005-0313

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload arbitrary files via certain parameters to upload.php or (2) read arbitrary files via certain parameters to download.php, and remote authenticated users to read, create, or delete arbitrary directories and files via the IMAP commands (3) CREATE, (4) EXAMINE, (5) SELECT, or (6) DELETE.

    Published: 27 Jan 2005
    4.3
    Medium

    CVE-2005-0314

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in user.php in Magic Winmail Server 4.0 Build 1112 allows remote attackers to inject arbitrary web script or HTML via the personal information fields.

    Published: 27 Jan 2005
    4.6
    Medium

    CVE-2005-0315

    Last Modified: 16 Apr 2026

    The FTP service in Magic Winmail Server 4.0 Build 1112 does not verify that the IP address in a PORT command is the same as the IP address of the user of the FTP session, which allows remote authenticated users to use the server as an intermediary for port scanning.

    Published: 27 Jan 2005
    2.1
    Low

    CVE-2005-0312

    Last Modified: 16 Apr 2026

    WarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access violation) via a CWD command with a crafted pathname, as demonstrated using a large string of "%s" sequences, possibly indicating a format string vulnerability.

    Published: 27 Jan 2005
    6.5
    Medium

    CVE-2005-0244

    Last Modified: 16 Apr 2026

    PostgreSQL 8.0.0 and earlier allows local users to bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command.

    Published: 27 Jan 2005
    5
    Medium

    CVE-2005-0246

    Last Modified: 16 Apr 2026

    The intagg contrib module for PostgreSQL 8.0.0 and earlier allows attackers to cause a denial of service (crash) via crafted arrays.

    Published: 27 Jan 2005
    7.5
    High

    CVE-2005-0198

    Last Modified: 16 Apr 2026

    A logic error in the CRAM-MD5 code for the University of Washington IMAP (UW-IMAP) server, when Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5) is enabled, does not properly enforce all the required conditions for successful authentication, which allows remote attackers to authenticate as arbitrary users.

    Published: 27 Jan 2005
    2.1
    Low

    CVE-2004-1340

    Last Modified: 16 Apr 2026

    Debian GNU/Linux 3.0 installs the libpam-radius-auth package with the pam_radius_auth.conf set to be world-readable, which allows local users to obtain sensitive information.

    Published: 26 Jan 2005
    7.2
    High

    CVE-2005-0162

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the get_internal_addresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x before 2.3.0, when compiled with XAUTH and PAM enabled, allows remote authenticated attackers to execute arbitrary code.

    Published: 26 Jan 2005
    7.2
    High

    CVE-2003-1021

    Last Modified: 16 Apr 2026

    The scosession program in OpenServer 5.0.6 and 5.0.7 allows local users to gain privileges via crafted strings on the commandline.

    Published: 26 Jan 2005
    4.6
    Medium

    CVE-2005-0078

    Last Modified: 16 Apr 2026

    The KDE screen saver in KDE before 3.0.5 does not properly check the return value from a certain function call, which allows attackers with physical access to cause a crash and access the desktop session.

    Published: 26 Jan 2005
    2.1
    Low

    CVE-2005-0204

    Last Modified: 16 Apr 2026

    Linux kernel before 2.6.9, when running on the AMD64 and Intel EM64T architectures, allows local users to write to privileged IO ports via the OUTS instruction.

    Published: 26 Jan 2005
    5
    Medium

    CVE-2005-0306

    Last Modified: 16 Apr 2026

    MercuryBoard 1.1.1 allows remote attackers to gain sensitive information via an HTTP request with the n parameter set to 0, which causes a divide-by-zero error and reveals the path in the resulting error message.

    Published: 25 Jan 2005
    4.3
    Medium

    CVE-2005-0307

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in MercuryBoard 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) s, (2) l, (3) a, (4) t, (5) to, or (6) re parameters.

    Published: 25 Jan 2005
    4.3
    Medium

    CVE-2005-0309

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) mod.php in Exponent 0.95 allow remote attackers to inject arbitrary web script or HTML via the module parameter.

    Published: 25 Jan 2005
    2.1
    Low

    CVE-2005-0077

    Last Modified: 16 Apr 2026

    The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.

    Published: 25 Jan 2005
    7.5
    High

    CVE-2005-0115

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in DataRescue Interactive Disassembler (IDA) Pro 4.7 allows attackers to execute arbitrary code via a PE file with an Import Address Table containing a long import library name.

    Published: 24 Jan 2005
    2.1
    Low

    CVE-2005-0072

    Last Modified: 16 Apr 2026

    zhcon before 0.2 does not drop privileges before reading a user configuration file, which allows local users to read arbitrary files.

    Published: 24 Jan 2005
    2.6
    Low

    CVE-2005-0145

    Last Modified: 16 Apr 2026

    Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.

    Published: 24 Jan 2005
    7.5
    High

    CVE-2005-0308

    Last Modified: 16 Apr 2026

    Buffer overflow in the wsprintf function in W32Dasm 8.93 and earlier allows remote attackers to execute arbitrary code via a large import or export function name.

    Published: 24 Jan 2005
    7.8
    High

    CVE-2005-0209

    Last Modified: 16 Apr 2026

    Netfilter in Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via crafted IP packet fragments.

    Published: 24 Jan 2005
    7.1
    High

    CVE-2005-0449

    Last Modified: 16 Apr 2026

    The netfilter/iptables module in Linux before 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) or bypass firewall rules via crafted packets, which are not properly handled by the skb_checksum_help function.

    Published: 24 Jan 2005
    7.2
    High

    CVE-2005-0193

    Last Modified: 16 Apr 2026

    Buffer overflow in the (1) -v and (2) -a switches in mRouter in iSync 1.5 in Mac OS X 10.3.7 and earlier allows local users to execute arbitrary code.

    Published: 22 Jan 2005
    5
    Medium

    CVE-2005-0112

    Last Modified: 16 Apr 2026

    The web-based administrative interface for 3Com OfficeConnect Wireless 11g Access Point (AP) 1.00.08, and possibly earlier versions before 1.03.07A, allows remote attackers to bypass authentication and obtain sensitive information by directly accessing the (1) config.bin (2) profile.wlp?PN=ggg or (3) event.logs URLs.

    Published: 22 Jan 2005
    7.5
    High

    CVE-2004-1005

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.

    Published: 22 Jan 2005
    5
    Medium

    CVE-2004-1092

    Last Modified: 16 Apr 2026

    Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by causing mc to free unallocated memory.

    Published: 22 Jan 2005
    7.2
    High

    CVE-2005-0020

    Last Modified: 16 Apr 2026

    Buffer overflow in playmidi before 2.4 allows local users to execute arbitrary code.

    Published: 22 Jan 2005
    7.5
    High

    CVE-2005-0566

    Last Modified: 16 Apr 2026

    Buffer overflow in Golden FTP Server Pro (goldenftpd) 2.x allows remote attackers to execute arbitrary code via a long RNTO command.

    Published: 22 Jan 2005
    7.2
    High

    CVE-2005-0016

    Last Modified: 16 Apr 2026

    Buffer overflow in the exported_display function in xatitv in gatos before 0.0.5 allows local users to execute arbitrary code.

    Published: 22 Jan 2005
    7.5
    High

    CVE-2005-0129

    Last Modified: 16 Apr 2026

    The Quick Buttons feature in Konversation 0.15 allows remote attackers to execute certain IRC commands via a channel name containing "%" variables, which are recursively expanded by the Server::parseWildcards function when the Part Button is selected.

    Published: 22 Jan 2005
    7.5
    High

    CVE-2005-0130

    Last Modified: 16 Apr 2026

    Certain Perl scripts in Konversation 0.15 allow remote attackers to execute arbitrary commands via shell metacharacters in (1) channel names or (2) song names that are not properly quoted when the user runs IRC scripts.

    Published: 22 Jan 2005
    5
    Medium

    CVE-2005-0131

    Last Modified: 16 Apr 2026

    The Quick Connection dialog in Konversation 0.15 inadvertently uses the user-provided password as the nickname instead of the user-provided nickname when connecting to the IRC server, which could leak the password to other users.

    Published: 22 Jan 2005
    4.6
    Medium

    CVE-2004-1181

    Last Modified: 16 Apr 2026

    htmlheadline before 21.8 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

    Published: 22 Jan 2005
    7.5
    High

    CVE-2004-1004

    Last Modified: 16 Apr 2026

    Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.

    Published: 22 Jan 2005
    7.5
    High

    CVE-2005-0103

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code by modifying a URL parameter to reference a URL on a remote web server that contains the code.

    Published: 22 Jan 2005
    5
    Medium

    CVE-2005-0075

    Last Modified: 16 Apr 2026

    prefs.php in SquirrelMail before 1.4.4, with register_globals enabled, allows remote attackers to inject local code into the SquirrelMail code via custom preference handlers.

    Published: 22 Jan 2005
    4.3
    Medium

    CVE-2005-0104

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to inject arbitrary web script or HTML via certain integer variables.

    Published: 22 Jan 2005
    4.3
    Medium

    CVE-2005-0227

    Last Modified: 16 Apr 2026

    PostgreSQL (pgsql) 7.4.x, 7.2.x, and other versions allows local users to load arbitrary shared libraries and execute code via the LOAD extension.

    Published: 21 Jan 2005
    2.1
    Low

    CVE-2005-0365

    Last Modified: 16 Apr 2026

    The dcopidlng script in KDE 3.2.x and 3.3.x creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.

    Published: 21 Jan 2005
    5
    Medium

    CVE-2005-0081

    Last Modified: 16 Apr 2026

    MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (crash) via an HTTP request with invalid headers.

    Published: 20 Jan 2005
    5
    Medium

    CVE-2005-0082

    Last Modified: 16 Apr 2026

    The sapdbwa_GetUserData function in MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (crash) via invalid parameters to the WebDAV handler code, which triggers a null dereference that causes the SAP DB Web Agent to crash.

    Published: 20 Jan 2005