5
    Medium

    CVE-2005-1325

    Last Modified: 18 May 2013

    set_lang.php in phpMyVisites 1.3 allows remote attackers to read and include arbitrary files via the mylang parameter.

    Source:Max Cerny
    Published:27 Apr 2005
    7.5
    High

    CVE-2005-1323

    Last Modified: 16 Apr 2026

    Buffer overflow in NetFtpd for NetTerm 5.1.1 and earlier allows remote attackers to execute arbitrary code via a long USER command.

    Source:Sergio Alvarez
    Published:27 Apr 2005
    7.5
    High

    CVE-2005-1312

    Last Modified: 29 Dec 2016

    PHP remote file inclusion vulnerability in Yappa-NG before 2.3.2 allows remote attackers to execute arbitrary PHP code via unknown vectors.

    Source:SHiKaA
    Published:24 Apr 2005
    7.5
    High

    CVE-2005-1308

    Last Modified: 18 May 2013

    SqWebMail allows remote attackers to inject arbitrary web script or HTML via CRLF sequences in the redirect parameter followed by the desired script or HTML.

    Source:Zinho
    Published:15 Apr 2005
    7.2
    High

    CVE-2005-1307

    Last Modified: 16 Apr 2026

    The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the productname.sh script, which allows local users to execute arbitrary code by copying and calling the scripts from a user-controlled directory.

    Source:Jonathan Bringhurst
    Published:17 May 2005
    7.5
    High

    CVE-2005-1306

    Last Modified: 30 May 2013

    The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulnerability."

    Source:Sverre H. Huseby
    Published:15 Jun 2005
    7.2
    High

    CVE-2005-1294

    Last Modified: 8 Dec 2016

    The affix_sock_register in the Affix Bluetooth Protocol Stack for Linux might allow local users to gain privileges via a socket call with a negative protocol value, which is used as an array index.

    Source:qobaiashi
    Published:24 Apr 2005
    7.5
    High

    CVE-2005-1293

    Last Modified: 18 May 2013

    Multiple SQL injection vulnerabilities in default.asp in StorePortal 2.63 allow remote attackers to execute arbitrary SQL commands via the (1) language, (2) bpic, (3) idcategory, (4) content, (5) keyword, or (6) idproduct parameter.

    Source:Dcrab
    Published:26 Apr 2005
    7.5
    High

    CVE-2005-1289

    Last Modified: 16 Apr 2026

    index.cgi in E-Cart 2004 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) art and possibly (2) cat parameters.

    Source:z
    Published:26 Apr 2005
    7.5
    High

    CVE-2005-1287

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in BK Forum 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to member.asp, (2) forum parameter to forum.asp, or (3) various parameters in register.asp.

    Source:n0m3rcy
    Published:23 Apr 2005
    6.8
    Medium

    CVE-2005-1285

    Last Modified: 17 May 2013

    Cross-site scripting (XSS) vulnerability in thread.php in WoltLab Burning Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the hilight parameter.

    Source:deluxe89
    Published:22 Apr 2005
    5
    Medium

    CVE-2005-1280

    Last Modified: 13 May 2016

    The rsvp_print function in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of length 4.

    Source:vade79
    Published:26 Apr 2005
    5
    Medium

    CVE-2005-1279

    Last Modified: 13 May 2016

    tcpdump 3.8.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted (1) BGP packet, which is not properly handled by RT_ROUTING_INFO, or (2) LDP packet, which is not properly handled by the ldp_print function.

    Source:vade79
    Published:26 Apr 2005
    5
    Medium

    CVE-2005-1278

    Last Modified: 13 May 2016

    The isis_print function, as called by isoclns_print, in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a zero length, as demonstrated using a GRE packet.

    Source:vade79
    Published:26 Apr 2005
    5
    Medium

    CVE-2005-1275

    Last Modified: 18 May 2013

    Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a PNM file with a small colors value.

    Source:Damian Put
    Published:24 Apr 2005
    7.5
    High

    CVE-2005-1272

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the Backup Agent for Microsoft SQL Server in BrightStor ARCserve Backup Agent for SQL Server 11.0 allows remote attackers to execute arbitrary code via a long string sent to port (1) 6070 or (2) 6050.

    Source:Metasploit
    Published:5 Aug 2005
    5
    Medium

    CVE-2005-1267

    Last Modified: 13 May 2016

    The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted BGP packet.

    Source:simon
    Published:6 Jun 2005
    7.2
    High

    CVE-2005-1263

    Last Modified: 23 May 2013

    The elf_core_dump function in binfmt_elf.c for Linux kernel 2.x.x to 2.2.27-rc2, 2.4.x to 2.4.31-pre1, and 2.6.x to 2.6.12-rc4 allows local users to execute arbitrary code via an ELF binary that, in certain conditions involving the create_elf_tables function, causes a negative length argument to pass a signed integer comparison, leading to a buffer overflow.

    Source:Paul Starzetz
    Published:11 May 2005
    7.5
    High

    CVE-2005-1261

    Last Modified: 13 May 2016

    Stack-based buffer overflow in the URL parsing function in Gaim before 1.3.0 allows remote attackers to execute arbitrary code via an instant message (IM) with a large URL.

    Source:Ron
    Published:11 May 2005
    10
    Critical

    CVE-2005-1255

    Last Modified: 5 Dec 2016

    Multiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allow remote attackers to execute arbitrary code via a LOGIN command with (1) a long username argument or (2) a long username argument that begins with a special character.

    Source:kingcope
    Published:25 May 2005
    7.5
    High

    CVE-2005-1250

    Last Modified: 1 Jun 2013

    SQL injection vulnerability in the logon screen of the web front end (NmConsole/Login.asp) for IpSwitch WhatsUp Professional 2005 SP1 allows remote attackers to execute arbitrary SQL commands via the (1) User Name field (sUserName parameter) or (2) Password (sPassword parameter).

    Source:anonymous
    Published:22 Jun 2005
    10
    Critical

    CVE-2005-1246

    Last Modified: 13 May 2016

    Format string vulnerability in the snmppd_log function in snmppd_util.c for snmppd 0.4.5 and earlier may allow remote attackers to cause a denial of service or execute arbitrary code via format string specifiers that are not properly handled in a syslog call.

    Source:cybertronic
    Published:24 Apr 2005
    7.5
    High

    CVE-2005-1237

    Last Modified: 5 Dec 2016

    SQL injection vulnerability in news.php in FlexPHPNews 0.0.3 allows remote attackers to execute arbitrary SQL commands via the newsid parameter.

    Source:Dj7xpl
    Published:24 Apr 2005
    7.5
    High

    CVE-2005-1236

    Last Modified: 16 May 2013

    Multiple SQL injection vulnerabilities in DUware DUportal 3.1.2 and 3.1.2 SQL allow remote attackers to execute arbitrary SQL commands via the (1) iChannel parameter to channel.asp or search.asp, (2) iData parameter to detail.asp or inc_rating.asp, (3) iCat parameter to detail.asp or type.asp, (4) DAT_PARENT parameter to inc_poll_voting.asp, or (5) iRate parameter to inc_rating.asp, a different set of vulnerabilities than CVE-2005-1224.

    Source:Dcrab
    Published:24 Apr 2005
    4.3
    Medium

    CVE-2005-1233

    Last Modified: 15 May 2013

    Cross-site scripting (XSS) vulnerability in index.php in PHP Labs proFile allows remote attackers to inject arbitrary web script or HTML via the (1) dir or (2) file parameters.

    Source:sNKenjoi
    Published:20 Apr 2005
    7.5
    High

    CVE-2005-1224

    Last Modified: 16 May 2013

    Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) nChannel parameter to default.asp, cat.asp, or detail.asp, (2) the iChannel parameter to search.asp, default.asp, result.asp, cat.asp, or detail.asp (3) the iCat parameter to cat.asp or detail.asp, (4) the iData parameter to detail.asp or result.asp, the (5) POL_ID, (6) POL_PARENT, (7) POL_CATEGORY, (8) CHA_NAME, or (9) CHA_ID parameters to inc_vote.asp, or the (10) tfm_order or (11) tfm_orderby parameters to toppages.asp, a different set of vulnerabilities than CVE-2005-1236.

    Source:Dcrab
    Published:22 Apr 2005
    7.5
    High

    CVE-2005-1223

    Last Modified: 15 May 2013

    Multiple SQL injection vulnerabilities in Ocean12 Calendar manager 1.01 allow remote attackers to execute arbitrary SQL commands via the Admin_id field.

    Source:Zinho
    Published:22 Apr 2005
    7.5
    High

    CVE-2005-1222

    Last Modified: 15 May 2013

    cat_for_gen.php in Annuaire Netref 4.2 allows remote attackers to execute arbitrary PHP code by setting the ad_direct parameter to reference cat_for_gen.php, then including the code in the m_for_racine parameter, which is then written to cat_for_gen.php.

    Source:jaguar
    Published:22 Apr 2005
    7.5
    High

    CVE-2005-1219

    Last Modified: 16 Apr 2026

    Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.

    Source:snooq
    Published:12 Jul 2005
    5
    Medium

    CVE-2005-1218

    Last Modified: 16 Apr 2026

    The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.

    Source:Tom Ferris
    Published:10 Aug 2005
    7.5
    High

    CVE-2005-1213

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field.

    Source:eyas
    Published:14 Jun 2005
    5
    Medium

    CVE-2005-1204

    Last Modified: 15 May 2013

    Desktop Rover 3.0, and possibly earlier versions, allows remote attackers to cause a denial of service (application crash) via a crafted packet to TCP port 61427, which causes an invalid memory access.

    Source:Adam Baldwin
    Published:21 Apr 2005
    7.5
    High

    CVE-2005-1203

    Last Modified: 5 Jan 2018

    Multiple SQL injection vulnerabilities in index.php in eGroupware before 1.0.0.007 allow remote attackers to execute arbitrary SQL commands via the (1) filter or (2) cats_app parameter.

    Source:GulfTech Security
    Published:21 Apr 2005
    6.8
    Medium

    CVE-2005-1202

    Last Modified: 5 Jan 2018

    Multiple cross-site scripting (XSS) vulnerabilities in eGroupware before 1.0.0.007 allow remote attackers to inject arbitrary web script or HTML via the (1) ab_id, (2) page, (3) type, or (4) lang parameter to index.php or (5) category_id parameter.

    Source:GulfTech Security
    Published:21 Apr 2005
    6.4
    Medium

    CVE-2005-1201

    Last Modified: 19 Jan 2018

    Multiple directory traversal vulnerabilities in AZ Bulletin board (AZbb) before 1.0.08 allow (1) remote authenticated users with administrative privileges to delete arbitrary files via a .. (dot dot) in the URL to admin_avatar.php or admin_attachment.php or (2) remote attackers to enumerate files via a .. (dot dot) in the attachment parameter to attachment.php, which displays a different message when a file exists or does not exist.

    Source:GulfTech Security
    Published:21 Apr 2005
    7.5
    High

    CVE-2005-1200

    Last Modified: 19 Jan 2018

    PHP remote file inclusion vulnerability in main_index.php in AZ Bulletin Board (AZbb) 1.0.07a through 1.0.07c allows remote attackers to execute arbitrary PHP code by modifying the (1) dir_src or (2) abs_layer parameter to reference a URL on a remote web server that contains the code.

    Source:GulfTech Security
    Published:21 Apr 2005
    7.5
    High

    CVE-2005-1199

    Last Modified: 14 May 2013

    SQL injection vulnerability in printthread.php in UBB.Threads allows remote attackers to execute arbitrary SQL commands via the main parameter.

    Source:HLL
    Published:21 Apr 2005
    7.5
    High

    CVE-2005-1196

    Last Modified: 14 May 2013

    SQL injection vulnerability in kb.php in the Knowledge Base module for phpBB allows remote attackers to obtain sensitive information and execute SQL commands via the cat parameter.

    Published:21 Apr 2005
    7.5
    High

    CVE-2005-1193

    Last Modified: 22 May 2013

    The bbencode_second_pass and make_clickable functions in bbcode.php for phpBB before 2.0.15, as used in viewtopic.php, privmsg.php, and other scripts, allow remote attackers to execute arbitrary script via a BBcode tag with a (1) javascript:, (2) applet:, (3) about:, (4) activex:, (5) chrome:, or (6) script: URI scheme, as demonstrated using the URL tag.

    Source:Papados
    Published:16 May 2005
    5
    Medium

    CVE-2005-1191

    Last Modified: 21 May 2013

    The Web View DLL (webvw.dll), as used in Windows Explorer on Windows 2000 systems, does not properly filter an apostrophe ("'") in the author name in a document, which allows attackers to execute arbitrary script via extra attributes when Web View constructs a mailto: link for the preview pane when the user selects the file.

    Source:GreyMagic Software
    Published:19 Apr 2005
    4.3
    Medium

    CVE-2005-1188

    Last Modified: 13 May 2013

    Cross-site scripting (XSS) vulnerability in comersus_searchItem.asp in Comersus 3.90 to 4.51 allows remote attackers to inject arbitrary web script or HTML via the curPage parameter.

    Source:Lostmon
    Published:19 Apr 2005
    5
    Medium

    CVE-2005-1184

    Last Modified: 14 May 2013

    The TCP/IP stack in multiple operating systems allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the correct sequence number but the wrong Acknowledgement number, which generates a large number of "keep alive" packets. NOTE: some followups indicate that this issue could not be replicated.

    Source:Antonio M. D. S. Fortes
    Published:19 Apr 2005
    4.3
    Medium

    CVE-2005-1183

    Last Modified: 14 May 2013

    Cross-site scripting (XSS) vulnerability in mvnForum 1.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the Search parameter.

    Source:hoang yen
    Published:19 Apr 2005
    7.5
    High

    CVE-2005-1181

    Last Modified: 14 May 2013

    NOTE: this issue has been disputed by the vendor. PHP remote code injection vulnerability in loader.php for Ariadne CMS 2.4 allows remote attackers to execute arbitrary PHP code by modifying the ariadne parameter to reference a URL on a remote web server that contains the code. NOTE: the vendor has disputed this issue, saying that loader.php first requires the "ariadne.inc" file, which defines the $ariadne variable, and thus it cannot be modified by an attacker. In addition, CVE personnel have partially verified the dispute via source code inspection of Ariadne 2.4 as available on July 5, 2005

    Source:Fidel Costa
    Published:19 Apr 2005
    7.5
    High

    CVE-2005-1173

    Last Modified: 29 Sept 2016

    Buffer overflow in PMSoftware Simple Web Server 1.0 allows remote attackers to execute arbitrary code via a long GET request.

    Source:cybertronic
    Published:18 Apr 2005
    4.3
    Medium

    CVE-2005-1171

    Last Modified: 14 May 2013

    Cross-site scripting (XSS) vulnerability in mod.php in the datenbank module for phpBB allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Source:tom cruise
    Published:18 Apr 2005
    7.5
    High

    CVE-2005-1170

    Last Modified: 14 May 2013

    SQL injection vulnerability in mod.php in the datenbank module for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:tom cruise
    Published:18 Apr 2005
    5
    Medium

    CVE-2005-1165

    Last Modified: 16 Apr 2026

    Yager 5.24 and earlier allows remote attackers to cause a denial of service (application crash) via certain malformed data.

    Source:Luigi Auriemma
    Published:18 Apr 2005
    5
    Medium

    CVE-2005-1164

    Last Modified: 16 Apr 2026

    Yager 5.24 and earlier allows remote attackers to cause a denial of service (application hang) via a packet with a game header that provides less data than indicated by the length.

    Source:Luigi Auriemma
    Published:18 Apr 2005
    6.4
    Medium

    CVE-2005-1163

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Yager 5.24 and earlier allow remote attackers to execute arbitrary code via (1) a crafted nickname or (2) a packet with a large amount of data.

    Source:cybertronic
    Published:18 Apr 2005