CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2004-1175

    Last Modified: 16 Apr 2026

    fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters.

    Published: 14 Jan 2005
    5
    Medium

    CVE-2004-1090

    Last Modified: 16 Apr 2026

    Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header."

    Published: 14 Jan 2005
    5
    Medium

    CVE-2004-1091

    Last Modified: 16 Apr 2026

    Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference.

    Published: 14 Jan 2005
    5
    Medium

    CVE-2005-0740

    Last Modified: 16 Apr 2026

    The TCP stack (tcp_input.c) in OpenBSD 3.5 and 3.6 allows remote attackers to cause a denial of service (system panic) via crafted values in the TCP timestamp option, which causes invalid arguments to be used when calculating the retransmit timeout.

    Published: 13 Jan 2005
    4.3
    Medium

    CVE-2005-0381

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in f.aspx in forumKIT 1.0 allows remote attackers to inject arbitrary web script or HTML via the members parameter.

    Published: 13 Jan 2005
    7.5
    High

    CVE-2005-0111

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long password parameter.

    Published: 13 Jan 2005
    5
    Medium

    CVE-2005-0456

    Last Modified: 16 Apr 2026

    Opera 7.54 and earlier does not properly validate base64 encoded binary data in a data: (RFC 2397) URL, which causes the URL to be obscured in a download dialog, which may allow remote attackers to trick users into executing arbitrary code.

    Published: 12 Jan 2005
    7.5
    High

    CVE-2005-0376

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in SGallery 1.01 allows local and possibly remote attackers to execute arbitrary PHP code by modifying the DOCUMENT_ROOT parameter to reference a URL on a remote web server that contains (1) config.php or (2) sql_layer.php.

    Published: 12 Jan 2005
    5
    Medium

    CVE-2005-0095

    Last Modified: 16 Apr 2026

    The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WCCP messages with source addresses that are spoofed to reference Squid's home router and invalid WCCP_I_SEE_YOU cache numbers.

    Published: 12 Jan 2005
    5
    Medium

    CVE-2005-0094

    Last Modified: 16 Apr 2026

    Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squid 2.5.STABLE7 and earlier allows remote malicious Gopher servers to cause a denial of service (crash) via crafted responses.

    Published: 12 Jan 2005
    6.9
    Medium

    CVE-2005-0001

    Last Modified: 16 Apr 2026

    Race condition in the page fault handler (fault.c) for Linux kernel 2.2.x to 2.2.7, 2.4 to 2.4.29, and 2.6 to 2.6.10, when running on multiprocessor machines, allows local users to execute arbitrary code via concurrent threads that share the same virtual memory space and simultaneously request stack expansion.

    Published: 12 Jan 2005
    7.5
    High

    CVE-2004-0991

    Last Modified: 16 Apr 2026

    Buffer overflow in mpg123 before 0.59s-r9 allows remote attackers to execute arbitrary code via frame headers in MP2 or MP3 files.

    Published: 11 Jan 2005
    5
    Medium

    CVE-2004-1039

    Last Modified: 16 Apr 2026

    The NFS mountd service on SCO UnixWare 7.1.1, 7.1.3, 7.1.4, and 7.0.1, and possibly other versions, when run from inetd, allows remote attackers to cause a denial of service (memory exhaustion) via a series of requests, which causes inetd to launch a separate process for each request.

    Published: 11 Jan 2005
    10
    Critical

    CVE-2004-0897

    Last Modified: 16 Apr 2026

    The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.

    Published: 11 Jan 2005
    5
    Medium

    CVE-2005-0108

    Last Modified: 16 Apr 2026

    Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument.

    Published: 11 Jan 2005
    4.6
    Medium

    CVE-2005-0117

    Last Modified: 16 Apr 2026

    Buffer overflow in XShisen before 1.36 allows local users to execute arbitrary code via a long GECOS field.

    Published: 11 Jan 2005
    3.6
    Low

    CVE-2005-0288

    Last Modified: 16 Apr 2026

    The change password functionality in Bottomline Webseries Payment Application does not require the old password when users enter a new password, which could allow remote authenticated users to change other users' passwords.

    Published: 11 Jan 2005
    2.1
    Low

    CVE-2005-3107

    Last Modified: 16 Apr 2026

    fs/exec.c in Linux 2.6, when one thread is tracing another thread that shares the same memory map, might allow local users to cause a denial of service (deadlock) by forcing a core dump when the traced thread is in the TASK_TRACED state.

    Published: 11 Jan 2005
    5
    Medium

    CVE-2005-0287

    Last Modified: 16 Apr 2026

    Bottomline Webseries Payment Application allows remote attackers to read arbitrary files on the network via a report template with modified ReportPath or ReportName values.

    Published: 10 Jan 2005
    7.5
    High

    CVE-2005-0284

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in addentry.php in Woltlab Burning Book 1.0 Gold, 1.1.1e, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the user-agent parameter.

    Published: 10 Jan 2005
    2.1
    Low

    CVE-2005-0124

    Last Modified: 16 Apr 2026

    The coda_pioctl function in the coda functionality (pioctl.c) for Linux kernel 2.6.9 and 2.4.x before 2.4.29 may allow local users to cause a denial of service (crash) or execute arbitrary code via negative vi.in_size or vi.out_size values, which may trigger a buffer overflow.

    Published: 10 Jan 2005
    4.3
    Medium

    CVE-2004-1177

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.

    Published: 10 Jan 2005
    7.5
    High

    CVE-2005-0173

    Last Modified: 16 Apr 2026

    squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a space at the beginning or end, which is ignored by the LDAP server.

    Published: 10 Jan 2005
    4.6
    Medium

    CVE-2005-0069

    Last Modified: 16 Apr 2026

    The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on temporary files.

    Published: 9 Jan 2005
    5
    Medium

    CVE-2005-0096

    Last Modified: 16 Apr 2026

    Memory leak in the NTLM fakeauth_auth helper for Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (memory consumption).

    Published: 8 Jan 2005
    5
    Medium

    CVE-2005-0097

    Last Modified: 16 Apr 2026

    The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message that triggers a NULL dereference.

    Published: 8 Jan 2005
    7.2
    High

    CVE-2004-1057

    Last Modified: 16 Apr 2026

    Multiple drivers in Linux kernel 2.4.19 and earlier do not properly mark memory with the VM_IO flag, which causes incorrect reference counts and may lead to a denial of service (kernel panic) when accessing freed kernel pages.

    Published: 7 Jan 2005
    3.6
    Low

    CVE-2005-0180

    Last Modified: 16 Apr 2026

    Multiple integer signedness errors in the sg_scsi_ioctl function in scsi_ioctl.c for Linux 2.6.x allow local users to read or modify kernel memory via negative integers in arguments to the scsi ioctl, which bypass a maximum length check before calling the copy_from_user and copy_to_user functions.

    Published: 7 Jan 2005
    2.1
    Low

    CVE-2005-0179

    Last Modified: 16 Apr 2026

    Linux kernel 2.4.x and 2.6.x allows local users to cause a denial of service (CPU and memory consumption) and bypass RLIM_MEMLOCK limits via the mlockall call.

    Published: 7 Jan 2005
    5
    Medium

    CVE-2005-2874

    Last Modified: 16 Apr 2026

    The is_path_absolute function in scheduler/client.c for the daemon in CUPS before 1.1.23 allows remote attackers to cause a denial of service (CPU consumption by tight loop) via a "..\.." URL in an HTTP request.

    Published: 7 Jan 2005
    4.3
    Medium

    CVE-2004-1318

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in namazu.cgi for Namazu 2.0.13 and earlier allows remote attackers to inject arbitrary HTML and web script via a query that starts with a tab ("%09") character, which prevents the rest of the query from being properly sanitized.

    Published: 6 Jan 2005
    5
    Medium

    CVE-2005-0182

    Last Modified: 16 Apr 2026

    The mod_dosevasive module 1.9 and earlier for Apache creates temporary files with predictable filenames, which could allow remote attackers to overwrite arbitrary files via a symlink attack.

    Published: 6 Jan 2005
    2.1
    Low

    CVE-2005-2553

    Last Modified: 16 Apr 2026

    The find_target function in ptrace32.c in the Linux kernel 2.4.x before 2.4.29 does not properly handle a NULL return value from another function, which allows local users to cause a denial of service (kernel crash/oops) by running a 32-bit ltrace program with the -i option on a 64-bit executable program.

    Published: 6 Jan 2005
    6.2
    Medium

    CVE-2004-1235

    Last Modified: 16 Apr 2026

    Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.

    Published: 6 Jan 2005
    5.1
    Medium

    CVE-2004-1183

    Last Modified: 16 Apr 2026

    Integer overflow in the tiffdump utility for libtiff 3.7.1 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted TIFF file.

    Published: 5 Jan 2005
    5
    Medium

    CVE-2005-0283

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in QwikiWiki allows remote attackers to read arbitrary files via a .. (dot dot) and a %00 at the end of the filename in the page parameter.

    Published: 4 Jan 2005
    7.5
    High

    CVE-2005-0280

    Last Modified: 16 Apr 2026

    Format string vulnerability in Soldner Secret Wars 30830 and earlier allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in a message.

    Published: 4 Jan 2005
    2.1
    Low

    CVE-2005-0207

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Linux kernel 2.4.x, 2.5.x, and 2.6.x allows NFS clients to cause a denial of service via O_DIRECT.

    Published: 4 Jan 2005
    2.6
    Low

    CVE-2005-0585

    Last Modified: 16 Apr 2026

    Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.

    Published: 4 Jan 2005
    5.8
    Medium

    CVE-2015-0480

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40 allows remote attackers to affect integrity and availability via unknown vectors related to Tools.

    Published: 4 Jan 2005
    5
    Medium

    CVE-2005-1080

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in filenames in a .jar file.

    Published: 4 Jan 2005
    7.2
    High

    CVE-2005-0021

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with more than 8 components, as demonstrated using the -be command line option, which triggers an overflow in the host_aton function, or (2) the -bh command line option or dnsdb PTR lookup, which triggers an overflow in the dns_build_reverse function.

    Published: 4 Jan 2005
    4.6
    Medium

    CVE-2005-0022

    Last Modified: 16 Apr 2026

    Buffer overflow in the spa_base64_to_bits function in Exim before 4.43, as originally obtained from Samba code, and as called by the auth_spa_client function, may allow attackers to execute arbitrary code during SPA authentication.

    Published: 4 Jan 2005
    7.5
    High

    CVE-2005-0268

    Last Modified: 16 Apr 2026

    Direct code injection vulnerability in FlatNuke 2.5.1 allows remote attackers to execute arbitrary PHP code by placing the code into the url_avatar field.

    Published: 3 Jan 2005
    10
    Critical

    CVE-2004-1312

    Last Modified: 16 Apr 2026

    A bug in the HTML parser in a certain Microsoft HTML library, as used in various third party products, may allow remote attackers to cause a denial of service via certain strings, as reported in GFI MailEssentials for Exchange 9 and 10, and GFI MailSecurity for Exchange 8, which causes emails to remain in IIS or Exchange mail queues.

    Published: 3 Jan 2005
    4.3
    Medium

    CVE-2005-0274

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) si, (3) page, or (4) ppuser parameters.

    Published: 3 Jan 2005
    7.5
    High

    CVE-2005-0271

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to showcat.php or (2) product parameter to addfav.php.

    Published: 3 Jan 2005
    4.3
    Medium

    CVE-2005-4838

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the example web applications for Jakarta Tomcat 5.5.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) el/functions.jsp, (2) el/implicit-objects.jsp, and (3) jspx/textRotate.jspx in examples/jsp2/, as demonstrated via script in a request to snp/snoop.jsp. NOTE: other XSS issues in the manager were simultaneously reported, but these require admin access and do not cross privilege boundaries.

    Published: 3 Jan 2005
    4.3
    Medium

    CVE-2005-0266

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in SugarCRM 1.X allows remote attackers to inject arbitrary web script or HTML via the (1) return_module, (2) return_action, (3) name, (4) module, or (5) record parameter.

    Published: 1 Jan 2005
    5.3
    Medium

    CVE-2004-2320

    Last Modified: 28 May 2026

    The default configuration of BEA WebLogic Server and Express 8.1 SP2 and earlier, 7.0 SP4 and earlier, 6.1 through SP6, and 5.1 through SP13 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting.

    Published: 31 Dec 2004