2.6
    Low

    CVE-2005-1686

    Last Modified: 24 May 2013

    Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string specifiers in the filename. NOTE: while this issue is triggered on the command line by the gedit user, it has been reported that web browsers and email clients could be configured to provide a file name as an argument to gedit, so there is a valid attack that crosses security boundaries.

    Source:jsk:exworm
    Published:20 May 2005
    7.5
    High

    CVE-2005-1681

    Last Modified: 24 May 2013

    PHP remote file inclusion vulnerability in common.php in phpATM 1.21, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the include_location parameter to index.php.

    Source:Ingvar Gilbert
    Published:20 May 2005
    5.1
    Medium

    CVE-2005-1679

    Last Modified: 24 May 2013

    Stack-based buffer overflow in the error directive in picasm 1.12b and earlier allows attackers to execute arbitrary code via a long error message.

    Source:Shaun Colley
    Published:20 May 2005
    6.5
    Medium

    CVE-2005-1674

    Last Modified: 19 Jan 2018

    Cross-Site Request Forgery (CSRF) vulnerability in Help Center Live allows remote attackers to perform actions as the administrator via a link or IMG tag to view.php.

    Source:GulfTech Security
    Published:19 May 2005
    7.5
    High

    CVE-2005-1673

    Last Modified: 19 Jan 2018

    Multiple SQL injection vulnerabilities in Help Center Live allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to index.php, (2) tid parameter to view.php, fid parameter to (3) download.php or (4) chat_download.php, (5) status parameter to icon.php, TICKET_tid parameter to (6) index.php or (7) view.php.

    Source:GulfTech Security
    Published:19 May 2005
    4.3
    Medium

    CVE-2005-1672

    Last Modified: 19 Jan 2018

    Multiple cross-site scripting (XSS) vulnerabilities in Help Center Live allow remote attackers to inject arbitrary web script or HTML via the (1) find parameter to index.php, (2) name or (3) message field of a chat request, or (4) the message body when opening a trouble ticket.

    Source:GulfTech Security
    Published:19 May 2005
    5
    Medium

    CVE-2005-1667

    Last Modified: 16 Apr 2026

    DataTrac Activity Console 1.1 allows remote attackers to cause a denial of service via a long HTTP GET request.

    Source:basher13
    Published:18 May 2005
    7.5
    High

    CVE-2005-1666

    Last Modified: 22 May 2013

    Multiple buffer overflows in Orenosv HTTP/FTP Server 0.8.1 allow remote authenticated users to cause a denial of service (server crash) and possibly execute arbitrary code via long arguments to FTP commands such as MKD, RMD, or DELE, which are processed by the (1) ftp_xlate_path, (2) ftp_is_canonical, or (3) os_fn_nativize functions, or (4) a long SSI command that is processed by the parse_cmd function in cgissi.exe.

    Source:Tan Chew Keong
    Published:18 May 2005
    5
    Medium

    CVE-2005-1655

    Last Modified: 22 May 2013

    AOL Instant Messenger 5.5.x and earlier allows remote attackers to cause a denial of service (client crash) via an invalid smiley icon location in the sml parameter of a font tag.

    Published:18 May 2005
    7.5
    High

    CVE-2005-1654

    Last Modified: 16 Apr 2026

    Hosting Controller 6.1 Hotfix 1.9 and earlier allows remote attackers to register arbitrary users via a direct request to addsubsite.asp with the loginname and password parameters set.

    Source:Mouse
    Published:18 May 2005
    5
    Medium

    CVE-2005-1649

    Last Modified: 16 Apr 2026

    The IPv6 support in Windows XP SP2, 2003 Server SP1, and Longhorn, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, a variant of CVE-2005-0688 and a reoccurrence of the "Land" vulnerability (CVE-1999-0016).

    Source:RusH
    Published:18 May 2005
    5
    Medium

    CVE-2005-1645

    Last Modified: 23 May 2013

    Keyvan1 ImageGallery stores the image.mdb database under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.

    Source:g0rellazz G0r
    Published:18 May 2005
    7.5
    High

    CVE-2005-1642

    Last Modified: 19 Jan 2018

    SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attackers to execute arbitrary SQL commands via the $email variable.

    Source:GulfTech Security
    Published:17 May 2005
    7.5
    High

    CVE-2005-1637

    Last Modified: 23 May 2013

    Multiple SQL injection vulnerabilities in NPDS 4.8 and 5.0 allow remote attackers to execute arbitrary SQL commands via the thold parameter to (1) comments.php or (2) pollcomments.php.

    Source:NoSP
    Published:17 May 2005
    7.5
    High

    CVE-2005-1633

    Last Modified: 24 May 2013

    Multiple SQL injection vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) anzahl_beitraege parameter to jgs_portal.php, 2) year parameter to (jgs_portal_statistik.php, 3) year parameter to (jgs_portal_beitraggraf.php, 4) tag parameter to (jgs_portal_viewsgraf.php, 5) year parameter to (jgs_portal_themengraf.php, 6) year parameter to (jgs_portal_mitgraf.php, 7) id parameter to jgs_portal_sponsor.php, or (8) the Accept-Language header to jgs_portal_log.php.

    Published:17 May 2005
    7.5
    High

    CVE-2005-1629

    Last Modified: 22 Nov 2017

    SQL injection vulnerability in member.php for Photopost PHP Pro allows remote attackers to execute arbitrary SQL commands via the verifykey parameter.

    Source:basher13
    Published:17 May 2005
    7.5
    High

    CVE-2005-1628

    Last Modified: 14 Sept 2016

    apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter.

    Source:Alpha_Programmer
    Published:17 May 2005
    4.3
    Medium

    CVE-2005-1620

    Last Modified: 23 May 2013

    Cross-site scripting (XSS) vulnerability in Skull-Splitter Guestbook 1.0, 2.0 and 2.2 allows remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message.

    Source:Morinex Eneco
    Published:16 May 2005
    4.3
    Medium

    CVE-2005-1619

    Last Modified: 23 May 2013

    Multiple cross-site scripting (XSS) vulnerabilities in (1) start_page.css.php3 (aka start-page.css.php3) or (2) style.css.php3 in PHPMyChat 0.14.5 allow remote attackers to inject arbitrary web script or HTML commands via the FontName parameter. NOTE: it was later reported that 0.14.5 is also affected.

    Source:Megasky
    Published:16 May 2005
    5
    Medium

    CVE-2005-1618

    Last Modified: 23 May 2013

    The YMSGR URL handler in Yahoo! Messenger 5.x through 6.0 allows remote attackers to cause a denial of service (disconnect) via a room login or a room join request packet with a third : (colon) and an & (ampersand), which causes Messenger to send a corrupted packet to the server, which triggers a disconnect from the server.

    Source:Torseq Tech
    Published:16 May 2005
    7.5
    High

    CVE-2005-1615

    Last Modified: 23 May 2013

    viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 may allow remote attackers to read sensitive data via the postorder parameter, which is not properly handled by textdb.inc.php, possibly due to a SQL injection vulnerability.

    Source:Morinex Eneco
    Published:16 May 2005
    6.8
    Medium

    CVE-2005-1614

    Last Modified: 23 May 2013

    Cross-site scripting (XSS) vulnerability in viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the postorder parameter.

    Source:Morinex Eneco
    Published:16 May 2005
    6.8
    Medium

    CVE-2005-1613

    Last Modified: 23 May 2013

    Cross-site scripting (XSS) vulnerability in member.php in Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to inject arbitrary web script or HTML via the reverse parameter in a list action.

    Source:Megasky
    Published:16 May 2005
    7.5
    High

    CVE-2005-1612

    Last Modified: 23 May 2013

    SQL injection vulnerability in read.php in Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to execute arbitrary SQL commands via the TID parameter.

    Source:Megasky
    Published:16 May 2005
    6.8
    Medium

    CVE-2005-1611

    Last Modified: 20 May 2013

    Cross-site scripting (XSS) vulnerability in WebX in Web Crossing 5.x allows remote attackers to inject arbitrary web script or HTML via a URL with an "@" followed by the desired script.

    Source:dr_insane
    Published:16 May 2005
    6.8
    Medium

    CVE-2005-1610

    Last Modified: 23 May 2013

    Cross-site scripting (XSS) vulnerability in security.php for Tru-Zone NukeET 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via a base64 encoded Codigo parameter.

    Source:Suko & Lostmon
    Published:16 May 2005
    4.6
    Medium

    CVE-2005-1606

    Last Modified: 22 May 2013

    H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, which allows local users to gain privileges.

    Source:Morning Wood
    Published:16 May 2005
    7.5
    High

    CVE-2005-1604

    Last Modified: 22 May 2013

    PHP Advanced Transfer Manager (phpATM) 1.21 allows remote attackers to upload arbitrary files via filenames containing multiple file extensions, as demonstrated using a filename ending in "php.ns", which allows execution of arbitrary PHP code.

    Source:tjomi4
    Published:16 May 2005
    5
    Medium

    CVE-2005-1603

    Last Modified: 16 Apr 2026

    NiteEnterprises Remote File Manager 1.0 allows remote attackers to cause a denial of service (crash) via a crafted string to TCP port 7080.

    Source:basher13
    Published:16 May 2005
    7.5
    High

    CVE-2005-1598

    Last Modified: 19 Jan 2018

    SQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via a crafted cookie password hash (pass_hash) that modifies the internal $pid variable.

    Source:GulfTech Security
    Published:16 May 2005
    4.3
    Medium

    CVE-2005-1597

    Last Modified: 19 Jan 2018

    Cross-site scripting (XSS) vulnerability in (1) search.php and (2) topics.php for Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the highlite parameter.

    Source:GulfTech Security
    Published:16 May 2005
    7.5
    High

    CVE-2005-1594

    Last Modified: 22 May 2013

    SQL injection vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Lostmon
    Published:16 May 2005
    6.8
    Medium

    CVE-2005-1593

    Last Modified: 22 May 2013

    Cross-site scripting (XSS) vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Source:Lostmon
    Published:16 May 2005
    4.6
    Medium

    CVE-2005-1590

    Last Modified: 13 Mar 2013

    The Altiris Client Service for Windows (ACLIENT.EXE) 6.0.88 allows local users to disable password protection and access the administrative interface by finding and showing the "Altiris Client Service" hidden window, disabling the password protection, disabling the "Hide client tray icon box" option, then opening the AClient tray icon and using the View Log File option, a different vulnerability than CVE-2004-2070.

    Source:Reed Arvin
    Published:16 May 2005
    7.2
    High

    CVE-2005-1589

    Last Modified: 4 Sept 2016

    The pkt_ioctl function in the pktcdvd block device ioctl handler (pktcdvd.c) in Linux kernel 2.6.12-rc4 and earlier calls the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space and allows local users to cause a denial of service and possibly execute arbitrary code, a similar vulnerability to CVE-2005-1264.

    Source:alert7
    Published:17 May 2005
    4.3
    Medium

    CVE-2005-1587

    Last Modified: 23 May 2013

    Cross-site scripting (XSS) vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to inject arbitrary web script or HTML via the sWord parameter.

    Source:Lostmon
    Published:14 May 2005
    4.3
    Medium

    CVE-2005-1561

    Last Modified: 23 May 2013

    Multiple cross-site scripting (XSS) vulnerabilities in post.asp in MaxWebPortal 1.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mod, (2) M, or (3) type parameter.

    Source:Zinho
    Published:11 May 2005
    5
    Medium

    CVE-2005-1552

    Last Modified: 23 May 2013

    GeoVision Digital Video Surveillance System 6.04, 6.1 and 7.0, when set to create JPEG images, does not properly protect an image even when a password and username is assigned, which may allow remote attackers to gain sensitive information via a direct request to the image.

    Source:Tirath Rai
    Published:14 May 2005
    7.5
    High

    CVE-2005-1550

    Last Modified: 22 May 2013

    easymsgb.pl in Easy Message Board allows remote attackers to execute arbitrary commands via shell metacharacters in the print parameter.

    Source:SoulBlack Group
    Published:14 May 2005
    7.5
    High

    CVE-2005-1548

    Last Modified: 22 May 2013

    SQL injection vulnerability in index.php in Advanced Guestbook 2.3.1 allows remote attackers to execute arbitrary SQL commands via the entry parameter.

    Source:Spy Hat
    Published:14 May 2005
    7.5
    High

    CVE-2005-1547

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the demo version of Bakbone Netvault, and possibly other versions, allows remote attackers to execute arbitrary commands via a large packet to port 20031.

    Source:nolimit
    Published:14 May 2005
    7.5
    High

    CVE-2005-1544

    Last Modified: 29 Jun 2016

    Stack-based buffer overflow in libTIFF before 3.7.2 allows remote attackers to execute arbitrary code via a TIFF file with a malformed BitsPerSample tag.

    Source:Agustin Gianni
    Published:14 May 2005
    7.5
    High

    CVE-2005-1543

    Last Modified: 7 Mar 2011

    Multiple stack-based and heap-based buffer overflows in Remote Management authentication (zenrem32.exe) on Novell ZENworks 6.5 Desktop and Server Management, ZENworks for Desktops 4.x, ZENworks for Servers 3.x, and Remote Management allows remote attackers to execute arbitrary code via (1) unspecified vectors, (2) type 1 authentication requests, and (3) type 2 authentication requests.

    Source:Metasploit
    Published:25 May 2005
    7.5
    High

    CVE-2005-1532

    Last Modified: 23 May 2013

    Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.

    Source:moz_bug_r_a4
    Published:12 May 2005
    7.2
    High

    CVE-2005-1528

    Last Modified: 28 Jul 2013

    Untrusted search path vulnerability in the crttrap command in QNX Neutrino RTOS 6.2.1 allows local users to load arbitrary libraries via a LD_LIBRARY_PATH environment variable that references a malicious library.

    Source:anonymous
    Published:31 Dec 2005
    7.5
    High

    CVE-2005-1526

    Last Modified: 1 Jun 2013

    PHP remote file inclusion vulnerability in config_settings.php in Cacti before 0.8.6e allows remote attackers to execute arbitrary PHP code via the config[include_path] parameter.

    Source:Maciej Piotr Falkiewicz
    Published:22 Jun 2005
    5
    Medium

    CVE-2005-1524

    Last Modified: 3 Jun 2013

    PHP file inclusion vulnerability in top_graph_header.php in Cacti 0.8.6d and possibly earlier versions allows remote attackers to execute arbitrary PHP code via the config[library_path] parameter.

    Source:Alberto Trivero
    Published:22 Jun 2005
    7.5
    High

    CVE-2005-1523

    Last Modified: 25 May 2016

    Format string vulnerability in imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via format string specifiers in the command tag for IMAP commands.

    Source:CoKi
    Published:26 May 2005
    7.5
    High

    CVE-2005-1520

    Last Modified: 26 May 2013

    Buffer overflow in the header_get_field_name function in header.c for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via a crafted e-mail.

    Source:infamous41md
    Published:26 May 2005
    5
    Medium

    CVE-2005-1507

    Last Modified: 22 May 2013

    Buffer overflow in the Tomcat plugin in 4d WebSTAR 5.33 and 5.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long URL.

    Source:Braden Thomas
    Published:11 May 2005