7.5
    High

    CVE-2005-2799

    Last Modified: 16 Apr 2026

    Buffer overflow in apply.cgi in Linksys WRT54G 3.01.03, 3.03.6, and possibly other versions before 4.20.7, allows remote attackers to execute arbitrary code via a long HTTP POST request.

    Source:Raphael Rigo
    Published:15 Sept 2005
    5
    Medium

    CVE-2005-2792

    Last Modified: 6 Jan 2017

    Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the custom_welcome_page parameter.

    Source:rgod
    Published:2 Sept 2005
    5
    Medium

    CVE-2005-2791

    Last Modified: 1 Jul 2013

    BFCommand & Control Server Manager BFCC 1.22_A and earlier, and BFVCC 2.14_B and earlier, allows remote attackers to cause a denial of service (refused new connections) via a series of connections and disconnections without sending the login command.

    Source:Luigi Auriemma
    Published:2 Sept 2005
    7.5
    High

    CVE-2005-2788

    Last Modified: 14 Jun 2013

    Multiple SQL injection vulnerabilities in Land Down Under (LDU) 801 and earlier allow remote attackers to execute arbitrary SQL commands via the c parameter to (1) events.php, (2) index.php, or (3) list.php.

    Source:matrix_killer
    Published:2 Sept 2005
    5
    Medium

    CVE-2005-2787

    Last Modified: 25 May 2016

    comment_delete_cgi.php in Simple PHP Blog allows remote attackers to delete arbitrary files via the comment parameter.

    Source:Kenneth Belva
    Published:2 Sept 2005
    4.3
    Medium

    CVE-2005-2783

    Last Modified: 14 Jun 2013

    Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML via nested, malformed URL BBCode tags.

    Source:slacker4ever_1
    Published:2 Sept 2005
    7.5
    High

    CVE-2005-2782

    Last Modified: 14 Jun 2013

    PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute arbitrary PHP code via an "ftp://" URL in the alpath parameter, which bypasses the incomplete blacklist that only checks for "http" and "https" URLs.

    Source:4Degrees
    Published:2 Sept 2005
    7.5
    High

    CVE-2005-2777

    Last Modified: 14 Jun 2013

    Looking Glass 20040427 allows remote attackers to execute arbitrary commands via shell metacharacters in the DNS lookup query field.

    Source:rgod
    Published:2 Sept 2005
    7.5
    High

    CVE-2005-2775

    Last Modified: 14 Jun 2013

    php_api.php in phpWebNotes 2.0.0 uses the extract function to modify key variables such as $t_path_core, which leads to a PHP file inclusion vulnerability that allows remote attackers to execute arbitrary PHP code via the t_path_core parameter.

    Published:2 Sept 2005
    9.8
    Critical

    CVE-2005-2773

    Last Modified: 27 Oct 2016

    HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.

    Source:Metasploit
    Published:2 Sept 2005
    7.5
    High

    CVE-2005-2772

    Last Modified: 19 Dec 2016

    Multiple stack-based buffer overflows in University of Minnesota gopher client 3.0.9 allow remote malicious servers to execute arbitrary code via (1) a long "+VIEWS:" reply, which is not properly handled in the VIfromLine function, and (2) certain arguments when launching third party programs such as a web browser from a web link, which is not properly handled in the FIOgetargv function.

    Source:vade79
    Published:2 Sept 2005
    4.3
    Medium

    CVE-2005-2769

    Last Modified: 14 Jun 2013

    Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 and possibly other versions allows remote attackers to inject arbitrary web script or HTML via an HTML e-mail containing tags with strings that contain ">" or other special characters, which is not properly sanitized by SqWebMail.

    Source:Jakob Balle
    Published:2 Sept 2005
    7.5
    High

    CVE-2005-2767

    Last Modified: 14 Jun 2013

    Buffer overflow in LeapFTP allows remote attackers to execute arbitrary code via a long Host string in a Site Queue (.lsq) file.

    Source:Sowhat
    Published:2 Sept 2005
    7.5
    High

    CVE-2005-2733

    Last Modified: 25 May 2016

    upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which could allow remote attackers to execute arbitrary code.

    Source:Kenneth Belva
    Published:29 Aug 2005
    7.5
    High

    CVE-2005-2729

    Last Modified: 14 Jun 2013

    The HTTP proxy in Astaro Security Linux 6.0 does not properly filter HTTP CONNECT requests to localhost, which allows remote attackers to bypass firewall rules and connect to local services.

    Source:Oliver Karow
    Published:29 Aug 2005
    2.1
    Low

    CVE-2005-2725

    Last Modified: 14 Jun 2013

    The inputtrap utility in QNX RTOS 6.1.0, 6.3, and possibly earlier versions does not properly check permissions when the -t flag is specified, which allows local users to read arbitrary files.

    Source:Julio Cesar Fort
    Published:29 Aug 2005
    4.3
    Medium

    CVE-2005-2721

    Last Modified: 14 Jun 2013

    Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) admin.php in Foojan PHP Weblog allow remote attackers to inject arbitrary web script or HTML via the Referer field in the HTTP header.

    Source:ali202
    Published:29 Aug 2005
    5
    Medium

    CVE-2005-2719

    Last Modified: 16 Apr 2026

    Ventrilo 2.1.2 through 2.3.0 allows remote attackers to cause a denial of service (application crash) via a status packet that contains less data than specified in the packet header sent to UDP port 3784.

    Source:Luigi Auriemma
    Published:29 Aug 2005
    10
    Critical

    CVE-2005-2715

    Last Modified: 22 Nov 2017

    Format string vulnerability in the Java user interface service (bpjava-msvc) daemon for VERITAS NetBackup Data and Business Center 4.5FP and 4.5MP, and NetBackup Enterprise/Server/Client 5.0, 5.1, and 6.0, allows remote attackers to execute arbitrary code via the COMMAND_LOGON_TO_MSERVER command.

    Source:Kevin Finisterre
    Published:12 Oct 2005
    6.8
    Medium

    CVE-2005-2713

    Last Modified: 6 Sept 2016

    passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local users to create arbitrary world-writable files as root by specifying an alternate file in the password database option.

    Source:vade79
    Published:31 Dec 2005
    5.1
    Medium

    CVE-2005-2710

    Last Modified: 7 Jun 2016

    Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via the (1) image handle or (2) timeformat attribute in a RealPix (.rp) or RealText (.rt) file.

    Source:c0ntex
    Published:26 Sept 2005
    4.6
    Medium

    CVE-2005-2709

    Last Modified: 6 Sept 2016

    The sysctl functionality (sysctl.c) in Linux kernel before 2.6.14.1 allows local users to cause a denial of service (kernel oops) and possibly execute code by opening an interface file in /proc/sys/net/ipv4/conf/, waiting until the interface is unregistered, then obtaining and modifying function pointers in memory that was used for the ctl_table.

    Source:Rémi Denis-Courmont
    Published:8 Nov 2005
    7.5
    High

    CVE-2005-2697

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search.php for MyBulletinBoard (MyBB) 1.00 Release Candidate 1 through 4 allows remote attackers to execute arbitrary SQL commands via the uid parameter. NOTE: this issue might overlap CVE-2005-0282.

    Source:Alpha_Programmer
    Published:25 Aug 2005
    7.5
    High

    CVE-2005-2694

    Last Modified: 16 Apr 2026

    Buffer overflow in WinAce 2.6.0.5, and possibly earlier versions, allows remote attackers to execute arbitrary code via a temporary (.tmp) file that contains an entry with a long file name.

    Source:ATmaCA
    Published:25 Aug 2005
    7.5
    High

    CVE-2005-2690

    Last Modified: 14 Jun 2013

    SQL injection vulnerability in the Downloads module in PostNuke 0.760-RC4b allows PostNuke administrators to execute arbitrary SQL commands via the show parameter to dl-viewdownload.php.

    Source:Maksymilian Arciemowicz
    Published:24 Aug 2005
    2.6
    Low

    CVE-2005-2689

    Last Modified: 14 Jun 2013

    Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.760-RC4b allows remote attackers to inject arbitrary web script or HTML via (1) the moderate parameter to the Comments module or (2) htmltext parameter to html/user.php.

    Source:Maksymilian Arciemowicz
    Published:24 Aug 2005
    7.5
    High

    CVE-2005-2683

    Last Modified: 14 Jun 2013

    Multiple SQL injection vulnerabilities in PHPKit 1.6.1 allow remote attackers to execute arbitrary SQL commands via the (1) letter parameter to login/member.php or (2) im_receiver parameter to login/imcenter.php.

    Source:phuket
    Published:23 Aug 2005
    7.5
    High

    CVE-2005-2675

    Last Modified: 14 Jun 2013

    Note: the vendor has disputed this issue. Multiple SQL injection vulnerabilities in Land Down Under (LDU) 800 allow remote attackers to execute arbitrary SQL commands via the (1) s or (2) m parameter to forums.php, (3) o, (4) w, (5) s, or (6) p parameter to list.php, (7) m parameter to journal.php, (8) x or (9) n parameter to forums.php, or (10) w parameter to links.php. NOTE: this issue has been disputed by the vendor, who says "None of the tricks written there are working, the variables are properly sanitized and no LDU version is affected.

    Source:matrix_killer
    Published:23 Aug 2005
    4.3
    Medium

    CVE-2005-2674

    Last Modified: 14 Jun 2013

    Note: the vendor has disputed this issue. Multiple cross-site scripting (XSS) vulnerabilities in Land Down Under (LDU) 800 allow remote attackers to inject arbitrary web script or HTML via the (1) c or (2) m parameters to index.php or (3) w parameter to journal.php. NOTE: this issue has been disputed by the vendor, who says "None of the tricks written there are working, the variables are properly sanitized and no LDU version is affected.

    Source:bl2k
    Published:23 Aug 2005
    7.5
    High

    CVE-2005-2673

    Last Modified: 14 Jun 2013

    SQL injection vulnerability in modcp.php in WoltLab Burning Board 2.2.2 and 2.3.3 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) x or (2) y parameters.

    Source:[R]
    Published:23 Aug 2005
    10
    Critical

    CVE-2005-2668

    Last Modified: 6 Mar 2011

    Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allow remote attackers to execute arbitrary code via unknown vectors.

    Source:Metasploit
    Published:23 Aug 2005
    7.5
    High

    CVE-2005-2665

    Last Modified: 25 May 2016

    Stack-based buffer overflow in expires.c in Elm 2.5 PL5 through PL7, and possibly other versions, allows remote attackers to execute arbitrary code via an e-mail message with a long Expires header.

    Source:c0ntex
    Published:20 Aug 2005
    7.5
    High

    CVE-2005-2661

    Last Modified: 21 Jun 2013

    Format string vulnerability in the ParseBannerAndCapability function in main.c for up-imapproxy 1.2.3 and 1.2.4 allows remote IMAP servers to execute arbitrary code via format string specifiers in a banner or capability line.

    Source:Steve Kemp
    Published:14 Oct 2005
    7.5
    High

    CVE-2005-2651

    Last Modified: 13 Jun 2013

    gorum/prod.php in Zorum 3.5 allows remote attackers to execute arbitrary code via shell metacharacters in the argv parameter.

    Source:rgod
    Published:21 Aug 2005
    4.3
    Medium

    CVE-2005-2649

    Last Modified: 13 Jun 2013

    Cross-site scripting (XSS) vulnerability in ATutor 1.5.1 allows remote attackers to inject arbitrary web script or HTML via (1) course parameter in login.php or (2) words parameter in search.php.

    Source:matrix_killer
    Published:21 Aug 2005
    5
    Medium

    CVE-2005-2648

    Last Modified: 13 Jun 2013

    Directory traversal vulnerability in index.php in W-Agora 4.2.0 and earlier allows remote attackers to read arbitrary files via the site parameter.

    Source:matrix_killer
    Published:21 Aug 2005
    7.5
    High

    CVE-2005-2644

    Last Modified: 13 Jun 2013

    Buffer overflow in JaguarEditControl.dll in Isemarket JaguarControl allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Jtext field.

    Source:Tacettin Karadeniz
    Published:21 Aug 2005
    5
    Medium

    CVE-2005-2640

    Last Modified: 13 Jun 2013

    Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to enumerate valid usernames via an IKE Aggressive Mode packet, which generates a response if the username is valid but does not respond when the username is invalid.

    Source:Roy Hills
    Published:20 Aug 2005
    7.5
    High

    CVE-2005-2639

    Last Modified: 16 Apr 2026

    Buffer overflow in Chris Moneymaker's World Poker Championship 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long nickname.

    Source:Luigi Auriemma
    Published:20 Aug 2005
    4.3
    Medium

    CVE-2005-2638

    Last Modified: 13 Jun 2013

    Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeNews 1.40 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) NewsMode parameter to NewsCategoryForm.php, or the (2) Match or (3) NewsMode parameter to SearchResults.php.

    Source:h4cky
    Published:20 Aug 2005
    7.5
    High

    CVE-2005-2637

    Last Modified: 13 Jun 2013

    Multiple SQL injection vulnerabilities in PHPFreeNews 1.40 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Match or (2) CatID parameter to SearchResults.php, or (3) the password to AccessControl.php.

    Source:h4cky
    Published:20 Aug 2005
    7.5
    High

    CVE-2005-2633

    Last Modified: 13 Jun 2013

    Multiple PHP file inclusion vulnerabilities in (1) admin_o.php, (2) board_o.php, (3) dev_o.php, (4) file_o.php or (5) tech_o.php in PHPTB Topic Board 2.0 and earlier allow remote attackers to execute arbitrary PHP code via the absolutepath parameter.

    Source:Filip Groszynski
    Published:20 Aug 2005
    5.1
    Medium

    CVE-2005-2629

    Last Modified: 30 Nov 2017

    Integer overflow in RealNetworks RealPlayer 8, 10, and 10.5, RealOne Player 1 and 2, and Helix Player 10.0.0 allows remote attackers to execute arbitrary code via an .rm movie file with a large value in the length field of the first data packet, which leads to a stack-based buffer overflow, a different vulnerability than CVE-2004-1481.

    Source:nolimit
    Published:10 Nov 2005
    7.5
    High

    CVE-2005-2616

    Last Modified: 13 Jun 2013

    Multiple PHP file include vulnerabilities in ezUpload 2.2 allow remote attackers to execute arbitrary code via the path parameter to (1) initialize.php, (2) customize.php, (3) form.php, or (4) index.php.

    Source:Johnnie Walker
    Published:17 Aug 2005
    7.5
    High

    CVE-2005-2612

    Last Modified: 4 May 2017

    Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP code via the cache_lastpostdate[server] cookie.

    Source:Metasploit
    Published:17 Aug 2005
    10
    Critical

    CVE-2005-2611

    Last Modified: 1 Apr 2017

    VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authentication from the NDMP agent to the server, which allows remote attackers to read and write arbitrary files with the backup server.

    Source:Metasploit
    Published:17 Aug 2005
    4.3
    Medium

    CVE-2005-2603

    Last Modified: 13 Jun 2013

    Cross-site scripting (XSS) vulnerability in index.php for My Image Gallery (Mig ) 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the (1) currDir or (2) image parameters.

    Source:anonymous
    Published:17 Aug 2005
    5
    Medium

    CVE-2005-2594

    Last Modified: 11 Jun 2013

    Apple Safari 1.3 (132) on Mac OS X 1.3.9 allows remote attackers to cause a denial of service (crash) via certain Javascript, possibly involving a function that defines a handler for itself within the function body.

    Source:Patrick Webster
    Published:17 Aug 2005
    4.3
    Medium

    CVE-2005-2588

    Last Modified: 11 Jun 2013

    Multiple cross-site scripting (XSS) vulnerabilities in DVBBS 7.1 SP2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the page parameter to dispbbs.asp, (2) name parameter to dispuser.asp, or the (3) title, (4) view, or (5) act parameter to boardhelp.asp.

    Source:Lostmon
    Published:17 Aug 2005
    7.5
    High

    CVE-2005-2587

    Last Modified: 13 Jun 2013

    SQL injection vulnerability in emailvalidate.php in PHPTB Topic Boards 2.0 allows remote attackers to execute arbitrary SQL commands via the mid parameter.

    Published:16 Aug 2005