4.6
    Medium

    CVE-2005-0713

    Last Modified: 6 May 2013

    The Bluetooth Setup Assistant for Mac OS X before 10.3.8 can be launched without a keyboard or Bluetooth device, which allows local users to bypass access restrictions and gain privileges.

    Source:V9
    Published:21 Mar 2005
    2.1
    Low

    CVE-2005-0711

    Last Modified: 5 May 2013

    MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allows local users with CREATE TEMPORARY TABLE privileges to overwrite arbitrary files via a symlink attack.

    Source:Marco Ivaldi
    Published:11 Mar 2005
    4.6
    Medium

    CVE-2005-0710

    Last Modified: 5 May 2013

    MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to bypass library path restrictions and execute arbitrary libraries by using INSERT INTO to modify the mysql.func table, which is processed by the udf_init function.

    Source:Stefano Di Paola
    Published:11 Mar 2005
    4.6
    Medium

    CVE-2005-0709

    Last Modified: 5 May 2013

    MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access libc calls, as demonstrated by using strcat, on_exit, and exit.

    Source:Stefano Di Paola
    Published:11 Mar 2005
    5
    Medium

    CVE-2005-0701

    Last Modified: 4 May 2013

    Directory traversal vulnerability in Oracle Database Server 8i and 9i allows remote attackers to read or rename arbitrary files via "\\.\\.." (modified dot dot backslash) sequences to UTL_FILE functions such as (1) UTL_FILE.FOPEN or (2) UTL_FILE.frename.

    Source:Cesar Cerrudo
    Published:7 Mar 2005
    5
    Medium

    CVE-2005-0700

    Last Modified: 16 Apr 2026

    The export_index action in myadmin.php for Aztek Forum 4.0 allows remote attackers to obtain database files, possibly by setting the ATK_ADMIN cookie.

    Source:sirius_black
    Published:7 Mar 2005
    4.6
    Medium

    CVE-2005-0698

    Last Modified: 28 Apr 2016

    PHP remote file inclusion vulnerability in PHPWebLog 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) G_PATH parameter to init.inc.php or the (2) PATH parameter to index.php to reference a URL on a remote web server that contains the code.

    Source:Filip Groszynski
    Published:7 Mar 2005
    7.5
    High

    CVE-2005-0691

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in article mode for modules.php in SocialMPN allows remote attackers to execute arbitrary PHP code by modifying the name parameter to reference a URL on a remote web server that contains the code.

    Source:y3dips
    Published:6 Mar 2005
    7.5
    High

    CVE-2005-0689

    Last Modified: 16 Apr 2026

    includer.cgi in The Includer allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the URL or (2) the template parameter.

    Source:Francisco Alisson
    Published:7 Mar 2005
    5
    Medium

    CVE-2005-0688

    Last Modified: 16 Apr 2026

    Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, aka a reoccurrence of the "Land" vulnerability (CVE-1999-0016).

    Source:Yuri Gushin
    Published:5 Mar 2005
    10
    Critical

    CVE-2005-0684

    Last Modified: 9 Mar 2011

    Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long file parameter after a percent ("%") sign or (2) a long Lock-Token string to the WebDAV functionality, which is not properly handled by the getLockTokenHeader function in WDVHandler_CommonUtils.c.

    Source:Metasploit
    Published:25 Apr 2005
    5
    Medium

    CVE-2005-0681

    Last Modified: 16 Apr 2026

    Nokia Symbian 60 allows remote attackers to cause a denial of service (phone restart) via a Bluetooth nickname.

    Source:Qnix
    Published:6 Mar 2005
    7.5
    High

    CVE-2005-0680

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in download_center_lite.inc.php for Download Center Lite 1.6 allows remote attackers to execute arbitrary PHP code by modifying the script_root parameter to reference a URL on a remote web server that contains the code.

    Source:Filip Groszynski
    Published:7 Mar 2005
    7.5
    High

    CVE-2005-0678

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in formmail.inc.php for Form Mail Script 2.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the script_root to reference a URL on a remote web server that contains the code.

    Source:Filip Groszynski
    Published:7 Mar 2005
    7.5
    High

    CVE-2005-0671

    Last Modified: 6 May 2013

    Format string vulnerability in Carsten's 3D Engine (Ca3DE), March 2004 version and earlier, allows remote attackers to execute arbitrary code via format string specifiers in a command.

    Source:Luigi Auriemma
    Published:3 Mar 2005
    4.3
    Medium

    CVE-2005-0670

    Last Modified: 3 May 2013

    Cross-site scripting (XSS) vulnerability in phpCOIN 1.2.0 through 1.2.1b allows remote attackers to inject arbitrary web script or HTML via (1) the new parameter to mod.php, (2) the w parameter to mod.php, (3) the e parameter to login.php, (4) the o parameter to login.php, and possibly other scripts.

    Source:Lostmon
    Published:7 Mar 2005
    4.6
    Medium

    CVE-2005-0666

    Last Modified: 16 Apr 2026

    Unknown vulnerability in PaX from the September 2003 release to 2.2 before 2005.03.05, related to SEGMEXEC or RANDEXEC and VMA mirroring, allows local users and possibly remote attackers to bypass intended access restrictions and execute arbitrary code.

    Source:Christophe Devine
    Published:7 Mar 2005
    4.3
    Medium

    CVE-2005-0650

    Last Modified: 4 May 2013

    Multiple cross-site scripting (XSS) vulnerabilities in ProjectBB 0.4.5.1 allow remote attackers to inject arbitrary web script or HTML via (1) the pages parameter to divers.php (incorrectly referred to as "drivers.php" by some sources), (2) in the search feature text area, (3) forum name, (4) site name or (5) the maximum avatar size in the option section, (5) new category or (6) new forum fields in the forum section.

    Source:benji lemien
    Published:4 Mar 2005
    5
    Medium

    CVE-2005-0647

    Last Modified: 16 Apr 2026

    admin_setup.php in paNews 2.0.4b allows remote attackers to inject arbitrary PHP code via the (1) $form[comments] or (2) $form[autoapprove] parameters, which are written to config.php.

    Source:Silentium
    Published:4 Mar 2005
    7.5
    High

    CVE-2005-0643

    Last Modified: 22 Jan 2013

    Buffer overflow in McAfee Scan Engine 4320 with DAT version before 4357 allows remote attackers to execute arbitrary code via crafted LHA files.

    Source:N4rK07IX
    Published:20 Mar 2005
    10
    Critical

    CVE-2005-0636

    Last Modified: 16 Apr 2026

    Format string vulnerability in Foxmail Server 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the USER command.

    Source:OYXin
    Published:2 Mar 2005
    10
    Critical

    CVE-2005-0635

    Last Modified: 16 Apr 2026

    Buffer overflow in Foxmail Server 2.0 allows remote attackers to execute arbitrary code via a long USER command.

    Source:Swan
    Published:4 Mar 2005
    7.5
    High

    CVE-2005-0634

    Last Modified: 28 Apr 2011

    Buffer overflow in Golden FTP Server 1.92 allows remote attackers to execute arbitrary code via a long USER command.

    Source:ATmaCA
    Published:4 Mar 2005
    7.5
    High

    CVE-2005-0633

    Last Modified: 28 Apr 2016

    Buffer overflow in Trillian 3.0 and Pro 3.0 allows remote attackers to execute arbitrary code via a crafted PNG image file.

    Source:Tal Zeltzer
    Published:2 Mar 2005
    5
    Medium

    CVE-2005-0632

    Last Modified: 5 Dec 2016

    PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP code via the path parameter.

    Source:mozako
    Published:1 Mar 2005
    4.3
    Medium

    CVE-2005-0629

    Last Modified: 7 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in profile.php in 427BB 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) Avatar parameters.

    Source:Hackerlounge Research Group
    Published:1 Mar 2005
    5
    Medium

    CVE-2005-0621

    Last Modified: 16 Apr 2026

    Scrapland 1.0 and earlier allows remote attackers to cause a denial of service (server termination) by triggering an error, which is treated as a fatal error by the server, as demonstrated using (1) signed integers for size values, (2) an invalid model, (3) a "newpos" value that is less than or equal to a size value, or (4) partial packets.

    Source:Luigi Auriemma
    Published:2 Mar 2005
    2.1
    Low

    CVE-2005-0619

    Last Modified: 16 Apr 2026

    Einstein 1.0.1 stores sensitive information such as usernames and passwords in plaintext in the registry, which allows local users to gain privileges.

    Source:Kozan
    Published:28 Feb 2005
    7.5
    High

    CVE-2005-0614

    Last Modified: 6 May 2016

    sessions.php in phpBB 2.0.12 and earlier allows remote attackers to gain administrator privileges via the autologinid value in a cookie.

    Source:Kutas
    Published:3 Mar 2005
    5
    Medium

    CVE-2005-0613

    Last Modified: 16 Apr 2026

    Unknown vulnerability in FCKeditor 2.0 RC2, when used with PHP-Nuke, allows remote attackers to upload arbitrary files.

    Source:BlackHawk
    Published:28 Feb 2005
    4.3
    Medium

    CVE-2005-0606

    Last Modified: 2 May 2013

    Cross-site scripting (XSS) vulnerability in settings.inc.php for CubeCart 2.0.0 through 2.0.5, as used in multiple PHP files, allows remote attackers to inject arbitrary HTML or web script via the (1) cat_id, (2) PHPSESSID, (3) view_doc, (4) product, (5) session, (6) catname, (7) search, or (8) page parameters.

    Source:Lostmon
    Published:1 Mar 2005
    5
    Medium

    CVE-2005-0603

    Last Modified: 16 Apr 2026

    viewtopic.php in phpBB 2.0.12 and earlier allows remote attackers to obtain sensitive information via a highlight parameter containing invalid regular expression syntax, which reveals the path in a PHP error message.

    Published:28 Feb 2005
    7.5
    High

    CVE-2005-0595

    Last Modified: 28 Apr 2011

    Buffer overflow in ext.dll in BadBlue 2.55 allows remote attackers to execute arbitrary code via a long mfcisapicommand parameter.

    Source:Metasploit
    Published:1 Mar 2005
    10
    Critical

    CVE-2005-0582

    Last Modified: 16 Apr 2026

    Buffer overflow in Computer Associates (CA) License Client 0.1.0.15 allows remote attackers to execute arbitrary code via a long filename in a PUTOLF request.

    Source:class101
    Published:2 Mar 2005
    4.6
    Medium

    CVE-2005-0581

    Last Modified: 3 Nov 2017

    Multiple buffer overflows in Computer Associates (CA) License Client and Server 0.1.0.15 allow remote attackers to execute arbitrary code via (1) certain long fields in the Checksum item in a GCR request, (2) a long IP address, hostname, or netmask values in a GCR request, (3) a long last parameter in a GETCONFIG packet, or (4) long values in a request with an invalid format.

    Source:Metasploit
    Published:2 Mar 2005
    7.5
    High

    CVE-2005-0575

    Last Modified: 27 Oct 2016

    Buffer overflow in Stormy Studios Knet 1.04c and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP GET request.

    Source:CorryL
    Published:27 Feb 2005
    7.5
    High

    CVE-2005-0569

    Last Modified: 14 Nov 2016

    Multiple SQL injection vulnerabilities in PunBB 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) language parameter to register.php, (2) change email feature in profile.php, (3) posts or (4) topics parameter to moderate.php.

    Source:John Gumbel
    Published:27 Feb 2005
    5
    Medium

    CVE-2005-0568

    Last Modified: 16 Apr 2026

    Soldier of Fortune II 1.03 gold allows remote attackers to cause a denial of service (application crash) via a large cl_guid value, which results in an invalid pointer dereference.

    Source:Luigi Auriemma
    Published:27 Feb 2005
    7.5
    High

    CVE-2005-0566

    Last Modified: 16 Apr 2026

    Buffer overflow in Golden FTP Server Pro (goldenftpd) 2.x allows remote attackers to execute arbitrary code via a long RNTO command.

    Source:Barabas
    Published:22 Jan 2005
    7.5
    High

    CVE-2005-0560

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server 2000 and 2003 allows remote attackers to execute arbitrary code via a crafted X-LINK2STATE extended verb request to the SMTP port.

    Source:Evgeny Pinchuk
    Published:13 Apr 2005
    7.5
    High

    CVE-2005-0555

    Last Modified: 13 May 2013

    Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka "Content Advisor Memory Corruption Vulnerability."

    Source:Miguel Tarasc
    Published:12 Apr 2005
    7.5
    High

    CVE-2005-0554

    Last Modified: 6 May 2016

    Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."

    Source:Skylined
    Published:13 Apr 2005
    5.1
    Medium

    CVE-2005-0553

    Last Modified: 21 May 2013

    Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".

    Source:Berend-Jan Wever
    Published:13 Apr 2005
    10
    Critical

    CVE-2005-0551

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value.

    Source:eyas
    Published:13 Apr 2005
    4.3
    Medium

    CVE-2005-0549

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the "View Log Files" function.

    Source:Thomas Liam Romanis
    Published:9 Mar 2005
    4.3
    Medium

    CVE-2005-0548

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search function.

    Source:Thomas Liam Romanis
    Published:7 Mar 2005
    4.3
    Medium

    CVE-2005-0543

    Last Modified: 2 May 2013

    Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cfg[BgcolorOne], or strServerChoice parameters in select_server.lib.php, (2) the bg_color or row_no parameters in display_tbl_links.lib.php, the left_font_family parameter in theme_left.css.php, or the right_font_family parameter in theme_right.css.php.

    Source:Maksymilian Arciemowicz
    Published:24 Feb 2005
    7.5
    High

    CVE-2005-0523

    Last Modified: 28 Apr 2016

    Format string vulnerability in ProZilla 1.3.7.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the Location header.

    Source:Serkan Akpolat
    Published:23 Feb 2005
    4.6
    Medium

    CVE-2005-0522

    Last Modified: 16 Apr 2026

    Chat Anywhere 2.72a stores sensitive information such as passwords in plaintext in the .INI file for a chatroom, which allows local users to gain privileges.

    Source:Kozan
    Published:23 Feb 2005
    2.1
    Low

    CVE-2005-0521

    Last Modified: 16 Apr 2026

    SendLink 1.5 stores sensitive information, possibly including passwords, in plaintext in the data.eat file, which allows local users to gain privileges.

    Source:Kozan
    Published:23 Feb 2005