2.1
    Low

    CVE-2005-1903

    Last Modified: 16 Apr 2026

    Buffer overflow in the IMAP service for SPA-PRO Mail @Solomon 4.00 allows remote authenticated users to execute arbitrary code via a long CREATE command.

    Source:Jerome Athias
    Published:2 Jun 2005
    5
    Medium

    CVE-2005-1899

    Last Modified: 12 Jun 2013

    Rakkarsoft RakNet network library 2.33 and earlier, when released before 30 May 2005, and as used in multiple products including nFusion Elite Warriors: Vietnam, allows remote attackers to cause a denial of service (infinite loop) via a zero-byte UDP packet.

    Source:Luigi Auriemma
    Published:8 Jun 2005
    4.3
    Medium

    CVE-2005-1895

    Last Modified: 29 May 2013

    Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the border or back parameters to (1) help.php or (2) footer.php.

    Source:SecWatch
    Published:8 Jun 2005
    7.5
    High

    CVE-2005-1894

    Last Modified: 29 May 2013

    Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be injected into referer.php, which can then be accessed by the attacker.

    Source:SecWatch
    Published:8 Jun 2005
    5
    Medium

    CVE-2005-1893

    Last Modified: 29 May 2013

    FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web document root in an error message.

    Source:SecWatch
    Published:8 Jun 2005
    4.3
    Medium

    CVE-2005-1886

    Last Modified: 29 May 2013

    Cross-site scripting (XSS) vulnerability in view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to inject arbitrary web script or HTML via (1) the phid parameter or (2) unknown parameters when posting a new comment.

    Source:anonymous
    Published:7 Jun 2005
    6.4
    Medium

    CVE-2005-1884

    Last Modified: 29 May 2013

    Directory traversal vulnerability in the (1) rmdir or (2) mkdir commands in upload.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to create or delete arbitrary directories via a .. (dot dot) in the dir parameter.

    Source:anonymous
    Published:7 Jun 2005
    7.5
    High

    CVE-2005-1882

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in last_gallery.php in YaPiG 0.93u and 0.94u allows remote attackers to execute arbitrary PHP code via the YAPIG_PATH parameter.

    Source:JIKO
    Published:7 Jun 2005
    7.5
    High

    CVE-2005-1881

    Last Modified: 29 May 2013

    upload.php in YaPiG 0.92b, 0.93u and 0.94u does not properly restrict the file extension for uploaded image files, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code.

    Source:anonymous
    Published:6 Jun 2005
    7.5
    High

    CVE-2005-1873

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Crob FTP 3.6.1, and possibly earlier versions, allow remote attackers to execute arbitrary code via (1) an FTP command with a large string followed by the RMD command with a long string or (2) a globbing ("*") character followed by a long string.

    Source:Leon Juranic
    Published:7 Jun 2005
    5
    Medium

    CVE-2005-1870

    Last Modified: 28 May 2013

    PHP remote file inclusion vulnerability in childwindow.inc.php in Popper 1.41-r2 and earlier allows remote attackers to execute arbitrary PHP code via the form parameter.

    Source:Leon Juranic
    Published:7 Jun 2005
    2.1
    Low

    CVE-2005-1858

    Last Modified: 29 May 2013

    FUSE 2.x before 2.3.0 does not properly clear previously used memory from unfilled pages when the filesystem returns a short byte count to a read request, which may allow local users to obtain sensitive information.

    Source:Miklos Szeredi
    Published:3 Jun 2005
    4.6
    Medium

    CVE-2005-1843

    Last Modified: 16 Apr 2026

    VCNative for Adobe Version Cue 1.0 and 1.0.1, as used in Creative Suite 1.0 and 1.3, and when running on Mac OS X with Version Cue Workspace, allows local users to load arbitrary libraries and execute arbitrary code via the -lib command line argument.

    Source:vade79
    Published:24 Aug 2005
    2.1
    Low

    CVE-2005-1842

    Last Modified: 16 Apr 2026

    VCNative for Adobe Version Cue 1.0 and 1.0.1, as used in Creative Suite 1.0 and 1.3, and when running on Mac OS X with Version Cue Workspace, creates temporary log files with predictable names, which allows local users to modify arbitrary files via a symlink attack.

    Source:vade79
    Published:24 Aug 2005
    7.5
    High

    CVE-2005-1833

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to calendar.php, (2) idsql parameter to online.php, (3) usersearch parameter to memberlist.php, (4) pid parameter to editpost.php, (5) fid parameter to forumdisplay.php, (6) tid parameter to newreply.php, (7) sid parameter to search.php, (8) tid or (9) pid parameter to showthread.php, (10) tid parameter to usercp2.php, (11) tid parameter to printthread.php, or (12) pid parameter to reputation.php.

    Source:Alberto Trivero
    Published:31 May 2005
    7.5
    High

    CVE-2005-1827

    Last Modified: 24 May 2013

    D-Link DSL-504T allows remote attackers to bypass authentication and gain privileges, such as upgrade firmware, restart the router or restore a saved configuration, via a direct request to firmwarecfg.

    Source:Francesco Orro
    Published:26 May 2005
    4.3
    Medium

    CVE-2005-1823

    Last Modified: 27 May 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) cat or (2) printable parameter to home.php, (3) productid or (4) mode parameter to product.php, (5) id parameter to error_message.php, (6) section parameter to help.php, (7) mode parameter to orders.php, (8) mode parameter to register.php, (9) mode parameter to search.php, or the (10) gcid or (11) gcindex parameter to giftcert.php.

    Source:CENSORED Search Vulnerabilities
    Published:1 Jun 2005
    7.5
    High

    CVE-2005-1822

    Last Modified: 27 May 2013

    Multiple SQL injection vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) printable parameter to home.php, (3) productid or (4) mode parameter to product.php, (5) id parameter to error_message.php, (6) section parameter to help.php, (7) mode parameter to orders.php, (8) mode parameter to register.php, (9) mode parameter to search.php, or the (10) gcid or (11) gcindex parameter to giftcert.php.

    Source:CENSORED Search Vulnerabilities
    Published:1 Jun 2005
    7.5
    High

    CVE-2005-1821

    Last Modified: 28 May 2013

    PHP remote file inclusion vulnerability in pdl_header.inc.php in PowerDownload 3.0.2 and 3.0.3 allows remote attackers to execute arbitrary PHP code via the incdir parameter to downloads.php.

    Source:SoulBlack Group
    Published:1 Jun 2005
    7.5
    High

    CVE-2005-1820

    Last Modified: 16 Apr 2026

    zboard.php in Zeroboard version 4.1pl2 to 4.1pl5 allows remote attackers to execute arbitrary PHP code via improper quoting when using the preg_replace function.

    Source:n0gada
    Published:1 Jun 2005
    5
    Medium

    CVE-2005-1817

    Last Modified: 27 May 2013

    Invision Power Board (IPB) 1.0 through 1.3 allows remote attackers to edit arbitrary forum posts via a direct request to index.php with modified parameters.

    Source:V[i]RuS
    Published:1 Jun 2005
    5
    Medium

    CVE-2005-1815

    Last Modified: 7 Mar 2011

    Multiple buffer overflows in Hummingbird Connectivity inetD 10.0.0.1 and 9.0.0.4 allows attackers to cause a denial of service and possibly execute arbitrary code via (1) an FTP command with a long argument to FTPD (ftpdw.exe) or (2) a large amount of data to LPD (Lpdw.exe).

    Source:Metasploit
    Published:1 Jun 2005
    10
    Critical

    CVE-2005-1812

    Last Modified: 16 Apr 2026

    Multiple stack-based buffer overflows in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allow remote attackers to execute arbitrary code via a long (1) filename or (2) transfer mode string in a Read Request (RRQ) or Write Request (WRQ) packet.

    Source:ATmaCA
    Published:1 Jun 2005
    5
    Medium

    CVE-2005-1807

    Last Modified: 22 Jun 2017

    The Data function in class.smtp.php in PHPMailer 1.7.2 and earlier allows remote attackers to cause a denial of service (infinite loop leading to memory and CPU consumption) via a long header field.

    Source:Mariano Nunez Di Croce
    Published:28 May 2005
    7.5
    High

    CVE-2005-1806

    Last Modified: 20 May 2016

    Format string vulnerability in PeerCast 0.1211 and earlier allows remote attackers to execute arbitrary code via format strings in the URL.

    Source:darkeagle
    Published:28 May 2005
    7.5
    High

    CVE-2005-1805

    Last Modified: 27 May 2013

    SQL injection vulnerability in login.asp in an unknown product by Online Solutions for Educators (OS4E) allows remote attackers to execute arbitrary SQL commands via the password.

    Source:Dj romty
    Published:28 May 2005
    7.5
    High

    CVE-2005-1804

    Last Modified: 27 Oct 2016

    Multiple SQL injection vulnerabilities in Net Portal Dynamic System (NPDS) 5.0 allow remote attackers to execute arbitrary SQL commands via the (1) terme parameter in the glossaire module (glossaire.php) or (2) query parameter to links.php.

    Source:NoSP
    Published:29 May 2005
    4.3
    Medium

    CVE-2005-1803

    Last Modified: 27 Oct 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Net Portal Dynamic System (NPDS) 5.0 allow remote attackers to inject arbitrary web script or HTML via the language parameter to (1) admin.php, or (2) powerpack_f.php, (3) the sitename parameter to sdv_infos.php, (4) the categories parameter to faq.php, (5) the lettre parameter to the glossaire module, (6) the title parameter to reviews.php, or (7) the image_subject parameter to reply.php.

    Source:NoSP
    Published:29 May 2005
    2.6
    Low

    CVE-2005-1801

    Last Modified: 27 May 2013

    The vCard viewer in Nokia 9500 allows attackers to cause a denial of service (crash) via a vCard with a long Name field, which causes the crash when the user views it.

    Source:Marek Bialoglowy
    Published:26 May 2005
    4.3
    Medium

    CVE-2005-1800

    Last Modified: 31 Jan 2017

    Cross-site scripting (XSS) vulnerability in Jaws Glossary gadget 0.4 to 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the term parameter in a view or ViewTerm action to index.php.

    Source:Nah
    Published:28 May 2005
    7.4
    High

    CVE-2005-1794

    Last Modified: 22 May 2026

    Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.

    Published:1 Jun 2005
    2.6
    Low

    CVE-2005-1790

    Last Modified: 14 Jan 2012

    Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."

    Source:Metasploit
    Published:1 Jun 2005
    7.5
    High

    CVE-2005-1788

    Last Modified: 27 May 2013

    SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands via the jresourceid parameter.

    Source:GrayHatz Security Group
    Published:1 Jun 2005
    7.5
    High

    CVE-2005-1787

    Last Modified: 13 May 2016

    setup.php in phpStat 1.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the $check variable.

    Source:Alpha_Programmer
    Published:27 May 2005
    7.5
    High

    CVE-2005-1784

    Last Modified: 16 Apr 2026

    Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parameter in an updateprofile action for UserProfile.asp.

    Source:Soroush Dalili
    Published:27 May 2005
    4.3
    Medium

    CVE-2005-1782

    Last Modified: 27 May 2013

    Multiple cross-site scripting (XSS) vulnerabilities in BookReview beta 1.0 allow remote attackers to inject arbitrary web script or HTML via the node parameter to (1) add_review.htm, (2) suggest_review.htm, (3) suggest_category.htm, (4) add_booklist.htm, or (5) add_url.htm, the isbn parameter to (6) add_review.htm, (7) add_contents.htm, (8) add_classification.htm, the (9) chapters parameter to the add_contents page in index.php (aka add_contents.htm), (10) the user parameter to contact.htm, or (11) the submit[string] parameter to search.htm. NOTE: it is not clear whether BookReview is available to the public. If not, then it should not be included in CVE.

    Source:Lostmon
    Published:26 May 2005
    7.5
    High

    CVE-2005-1779

    Last Modified: 14 Sept 2016

    SQL injection vulnerability in password.asp in MaxWebPortal 1.35, 1.36, 2.0, and 20050418 Next allows remote attackers to execute arbitrary SQL commands via the memKey parameter.

    Source:Soroush Dalili
    Published:31 May 2005
    7.5
    High

    CVE-2005-1777

    Last Modified: 13 May 2016

    SQL injection vulnerability in readpmsg.php in PostNuke 0.750 allows remote attackers to execute arbitrary SQL commands via the start parameter.

    Source:K-C0d3r
    Published:31 May 2005
    5
    Medium

    CVE-2005-1754

    Last Modified: 26 May 2013

    JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary files via a full pathname in the argument to the Download parameter. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products.

    Source:Ricky Latt
    Published:31 Dec 2005
    6.4
    Medium

    CVE-2005-1752

    Last Modified: 24 May 2013

    viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file_name parameter.

    Source:Filippo Spike Morelli
    Published:31 Dec 2005
    5
    Medium

    CVE-2005-1741

    Last Modified: 28 May 2013

    Gearbox Software Halo: Combat Evolved 1.6 allows remote attackers to cause a denial of service (infinite loop) via malformed data.

    Source:Luigi Auriemma
    Published:24 May 2005
    2.1
    Low

    CVE-2005-1725

    Last Modified: 16 Apr 2026

    launchd 106 in Apple Mac OS X 10.4.x up to 10.4.1 allows local users to overwrite arbitrary files via a symlink attack on the socket file in an insecure temporary directory.

    Source:intropy
    Published:8 Jun 2005
    5
    Medium

    CVE-2005-1718

    Last Modified: 28 May 2013

    Buffer overflow in LS Games War Times 1.03 and earlier allows remote attackers to cause a denial of service (server crash) via a long nickname.

    Source:Luigi Auriemma
    Published:24 May 2005
    4.3
    Medium

    CVE-2005-1715

    Last Modified: 24 May 2013

    Cross-site scripting (XSS) vulnerability in index.php for TOPo 2.2 (2.2.178) allows remote attackers to inject arbitrary web script or HTML via the (1) m, (2) s, (3) ID, or (4) t parameters, or the (5) field name, (6) Your Web field, or (7) email field in the comments section.

    Source:Lostmon
    Published:24 May 2005
    7.5
    High

    CVE-2005-1709

    Last Modified: 26 May 2013

    Unknown vulnerability in Blue Coat Reporter before 7.1.2 allows remote unauthenticated attackers to add a license.

    Source:Oliver Karow
    Published:24 May 2005
    4.6
    Medium

    CVE-2005-1708

    Last Modified: 26 May 2013

    templates.admin.users.user_form_processing in Blue Coat Reporter before 7.1.2 allows authenticated users to gain administrator privileges via an HTTP POST that sets volatile.user.administrator to true.

    Source:Oliver Karow
    Published:24 May 2005
    4.6
    Medium

    CVE-2005-1707

    Last Modified: 26 May 2013

    The fn_show_postinst function in Gentoo webapp-config before 1.10-r14 allows local users to overwrite arbitrary files via a symlink attack on the postinst.txt temporary file.

    Source:Eric Romang
    Published:24 May 2005
    5
    Medium

    CVE-2005-1703

    Last Modified: 28 May 2013

    Warrior Kings: Battles 1.23 and earlier allows remote attackers to cause a denial of service (server crash) via a partial join packet that triggers a NULL pointer dereference.

    Source:Luigi Auriemma
    Published:24 May 2005
    7.5
    High

    CVE-2005-1702

    Last Modified: 28 May 2013

    Format string vulnerability in Warrior Kings: Battles 1.23 and earlier and Warrior Kings 1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a nickname.

    Source:Luigi Auriemma
    Published:24 May 2005
    7.5
    High

    CVE-2005-1701

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in PortailPHP 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter to the (1) News, (2) File, (3) Liens, or (4) Faq modules.

    Source:Alberto Trivero
    Published:24 May 2005