2.1
    Low

    CVE-2005-0518

    Last Modified: 16 Apr 2026

    eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local users to gain privileges via the proxy_user and proxy_password values.

    Source:Kozan
    Published:23 Feb 2005
    2.1
    Low

    CVE-2005-0517

    Last Modified: 16 Apr 2026

    PeerFTP_5 stores sensitive information such as passwords in plaintext in the PeerFTP.ini files, which allows local users to gain privileges.

    Source:Kozan
    Published:23 Feb 2005
    7.5
    High

    CVE-2005-0513

    Last Modified: 1 May 2013

    PHP remote file inclusion vulnerability in mail_autocheck.php in the Email This Entry add-on for pMachine Pro 2.4, and possibly other versions including pMachine Free, allows remote attackers to execute arbitrary PHP code by directly requesting mail_autocheck.php and modifying the pm_path parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2003-1086.

    Source:kc
    Published:19 Feb 2005
    7.5
    High

    CVE-2005-0511

    Last Modified: 6 Mar 2011

    misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.

    Source:Metasploit
    Published:21 Feb 2005
    5
    Medium

    CVE-2005-0506

    Last Modified: 16 Apr 2026

    The Avaya IP Office Phone Manager, and other products such as the IP Softphone, stores sensitive data in cleartext in a registry key, which allows local and possibly remote users to steal usernames and passwords and impersonate other users via keys such as Avaya\IP400\Generic.

    Source:Adrian _pagvac_ Pastor
    Published:22 Feb 2005
    7.5
    High

    CVE-2005-0494

    Last Modified: 16 Apr 2026

    The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly validate the password before performing changes, which allows remote attackers on the LAN to gain access via a direct POST request.

    Source:MurDoK
    Published:21 Feb 2005
    10
    Critical

    CVE-2005-0491

    Last Modified: 5 Dec 2016

    Stack-based buffer overflow in Knox Arkeia Server Backup 5.3.x allows remote attackers to execute arbitrary code via a long type 77 request.

    Source:anonymous
    Published:21 Feb 2005
    5
    Medium

    CVE-2005-0479

    Last Modified: 1 May 2013

    Directory traversal vulnerability in ComGetLogFile.php3 for TrackerCam 5.12 and earlier allows remote attackers to read arbitrary files via ".." sequences and (1) "/" slash), (2) "\" (backslash), or (3) hex-encoded characters in the fn parameter.

    Source:Luigi Auriemma
    Published:19 Feb 2005
    5
    Medium

    CVE-2005-0478

    Last Modified: 7 Mar 2011

    Multiple buffer overflows in TrackerCam 5.12 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) an HTTP request with a long User-Agent header or (2) a long argument to an arbitrary PHP script.

    Source:Metasploit
    Published:19 Feb 2005
    4.3
    Medium

    CVE-2005-0477

    Last Modified: 8 Jan 2018

    Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote attackers to inject arbitrary web script via (1) a signature file or (2) a message post containing an IMG tag within a COLOR tag whose style is set to background:url.

    Source:Daniel A.
    Published:19 Feb 2005
    6.4
    Medium

    CVE-2005-0475

    Last Modified: 1 May 2013

    SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQL code via the (1) offset, (2) limit, (3) order, or (4) orderby parameter to question.php, (5) offset parameter to answer.php, (6) search_item parameter to search.php, (7) cat_id, (8) cid, or (9) id parameter to comment.php.

    Source:pi3ch
    Published:19 Feb 2005
    7.5
    High

    CVE-2005-0468

    Last Modified: 8 May 2013

    Heap-based buffer overflow in the env_opt_add function in telnet.c for various BSD-based Telnet clients allows remote attackers to execute arbitrary code via responses that contain a large number of characters that require escaping, which consumers more memory than allocated.

    Source:Gael Delalleau
    Published:28 Mar 2005
    2.1
    Low

    CVE-2005-0465

    Last Modified: 11 May 2013

    gr_osview in SGI IRIX does not drop privileges before opening files, which allows local users to overwrite arbitrary files via the -s option.

    Source:anonymous
    Published:8 Apr 2005
    2.1
    Low

    CVE-2005-0464

    Last Modified: 11 May 2013

    gr_osview in SGI IRIX 6.5.22, and possibly other 6.5 versions, does not drop privileges when opening description files while in debug mode, which allows local users to read a line from arbitrary files via the -d and -D options, which prints the line as a formatting error.

    Source:anonymous
    Published:8 Apr 2005
    5.1
    Medium

    CVE-2005-0455

    Last Modified: 27 Oct 2016

    Stack-based buffer overflow in the CSmil1Parser::testAttributeFailed function in smlparse.cpp for RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1 allows remote attackers to execute arbitrary code via a .SMIL file with a large system-screen-size value.

    Source:nolimit
    Published:24 Feb 2005
    4.3
    Medium

    CVE-2005-0452

    Last Modified: 1 May 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "<".

    Source:Andrey Rusyaev
    Published:16 Feb 2005
    4.3
    Medium

    CVE-2005-0443

    Last Modified: 4 Nov 2016

    index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-site scripting (XSS) attacks via an invalid language parameter, which echoes the parameter in a PHP error message.

    Source:John Cobb
    Published:15 Feb 2005
    5
    Medium

    CVE-2005-0442

    Last Modified: 30 Apr 2013

    Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via the language parameter.

    Source:John Cobb
    Published:15 Feb 2005
    7.5
    High

    CVE-2005-0439

    Last Modified: 28 Apr 2016

    Buffer overflow in the decode_post function in ELOG before 2.5.7 allows remote attackers to execute arbitrary code via attachments with long file names.

    Source:n4rk0tix
    Published:15 Feb 2005
    5
    Medium

    CVE-2005-0438

    Last Modified: 16 Apr 2026

    awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter.

    Source:omin0us
    Published:15 Feb 2005
    7.5
    High

    CVE-2005-0436

    Last Modified: 16 Apr 2026

    Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the PluginMode parameter.

    Source:GHC
    Published:15 Feb 2005
    5
    Medium

    CVE-2005-0435

    Last Modified: 16 Apr 2026

    awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to rawlog.

    Source:GHC
    Published:15 Feb 2005
    5
    Medium

    CVE-2005-0430

    Last Modified: 16 Apr 2026

    The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash the server via a long infostring, possibly triggering a buffer overflow.

    Source:Luigi Auriemma
    Published:12 Feb 2005
    5
    Medium

    CVE-2005-0429

    Last Modified: 16 Apr 2026

    Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled, allows remote attackers to execute inject arbitrary PHP commands via the comma parameter.

    Source:AL3NDALEEB
    Published:15 Feb 2005
    2.1
    Low

    CVE-2005-0422

    Last Modified: 16 Apr 2026

    DelphiTurk CodeBank (aka KodBank) 3.1 and earlier stores usernames and passwords in the Codebank registry key, which allows local users to gain privileges.

    Source:Kozan
    Published:15 Feb 2005
    2.1
    Low

    CVE-2005-0421

    Last Modified: 16 Apr 2026

    DelphiTurk FTP 1.0 stores usernames and passwords in the profile.dat file, which allows local users to gain privileges.

    Source:Kozan
    Published:15 Feb 2005
    5.8
    Medium

    CVE-2005-0420

    Last Modified: 29 Apr 2013

    Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login via a link to the owalogon.asp application.

    Source:Morning Wood
    Published:15 Feb 2005
    7.5
    High

    CVE-2005-0419

    Last Modified: 22 Nov 2017

    Multiple heap-based buffer overflows in 3Com 3CServer allow remote authenticated users to execute arbitrary code via long FTP commands, as demonstrated using the STAT command.

    Source:mandragore
    Published:15 Feb 2005
    7.5
    High

    CVE-2005-0416

    Last Modified: 16 Apr 2026

    The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allows remote attackers to execute arbitrary code via the AnimationHeaderBlock length field, which leads to a stack-based buffer overflow.

    Source:Vertygo
    Published:14 Feb 2005
    7.5
    High

    CVE-2005-0414

    Last Modified: 28 Apr 2016

    SQL injection vulnerability in post.php for MercuryBoard 1.1.1 allows remote attackers to execute arbitrary SQL commands via a reply post action for index.php with (1) the t parameter or (2) the qu parameter.

    Source:Zeelock
    Published:14 Feb 2005
    7.5
    High

    CVE-2005-0413

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the fid in forum.php, (2) the member parameter in member.php, (3) the email parameter in forgot.php, or (4) the nbuser or nbpass parameters in include.php. NOTE: it was later reported that vector 2 exists in 3.0 and earlier.

    Source:GHC
    Published:14 Feb 2005
    7.5
    High

    CVE-2005-0411

    Last Modified: 30 Apr 2013

    Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and local users to include arbitrary PHP files via .. (dot dot) sequences in the load parameter.

    Source:RedTeam Pentesting
    Published:14 Feb 2005
    5
    Medium

    CVE-2005-0410

    Last Modified: 30 Apr 2013

    SQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and earlier allows remote attackers to inject data via the fields of a CSV file.

    Source:RedTeam Pentesting
    Published:14 Feb 2005
    6.4
    Medium

    CVE-2005-0409

    Last Modified: 30 Apr 2013

    CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit card data, and facilitates the exploitation of other vulnerabilities.

    Source:RedTeam Pentesting
    Published:14 Feb 2005
    9.8
    Critical

    CVE-2005-0408

    Last Modified: 30 Apr 2013

    CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to bypass authentication and gain privileges by calculating the MD5 checksum of the user name combined with the "boogaadeeboo" string, which is hard-coded in the $hidden_hash variable.

    Source:RedTeam Pentesting
    Published:14 Feb 2005
    5
    Medium

    CVE-2005-0404

    Last Modified: 12 May 2013

    KMail 1.7.1 in KDE 3.3.2 allows remote attackers to spoof email information, such as whether the email has been digitally signed or encrypted, via HTML formatted email.

    Source:Noam Rathaus
    Published:13 Apr 2005
    7.2
    High

    CVE-2005-0385

    Last Modified: 16 Apr 2026

    Buffer overflow in luxman before 0.41, if used with certain insecure svgalib libraries, allows local users to execute arbitrary code via a long -f command line argument.

    Source:Kevin Finisterre
    Published:17 Mar 2005
    5
    Medium

    CVE-2005-0382

    Last Modified: 16 Apr 2026

    Breed patch 1 and earlier allows remote attackers to cause a denial of service (application crash) via an empty UDP packet, which triggers a null dereference.

    Source:Luigi Auriemma
    Published:13 Feb 2005
    5
    Medium

    CVE-2005-0370

    Last Modified: 16 Apr 2026

    Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (network disconnection) via an empty UDP packet, which is not properly distinguished from the "no new packets" state of the associated socket.

    Source:Luigi Auriemma
    Published:11 Feb 2005
    5.3
    Medium

    CVE-2005-0369

    Last Modified: 16 Apr 2026

    Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a packet with a large (1) descriptor ID or (2) claim_id, which exceeds the boundaries of an array.

    Source:Luigi Auriemma
    Published:11 Feb 2005
    7.5
    High

    CVE-2005-0368

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in CMScore allow remote attackers to execute arbitrary SQL commands via the (1) EntryID or (2) searchterm parameter to index.php, or (3) username parameter to authenticate.php.

    Source:GHC
    Published:11 Feb 2005
    5
    Medium

    CVE-2005-0356

    Last Modified: 16 Apr 2026

    Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.

    Source:Daniel Hartmeier
    Published:31 May 2005
    10
    Critical

    CVE-2005-0353

    Last Modified: 27 Oct 2016

    Buffer overflow in the Sentinel LM (Lservnt) service in the Sentinel License Manager 7.2.0.2 allows remote attackers to execute arbitrary code by sending a large amount of data to UDP port 5093.

    Source:Metasploit
    Published:8 Mar 2005
    5
    Medium

    CVE-2005-0345

    Last Modified: 22 Nov 2016

    viewthread.php in php-fusion 4.x does not check the (1) forum_id or (2) forum_cat parameters, which allows remote attackers to view protected forums via the thread_id parameter.

    Source:TheGreatOne2176
    Published:10 Feb 2005
    5
    Medium

    CVE-2005-0344

    Last Modified: 30 Apr 2013

    Directory traversal vulnerability in 602LAN SUITE 2004.0.04.1221 allows remote authenticated users to upload and execute arbitrary files via a .. (dot dot) in the filename parameter.

    Source:Tan Chew Keong
    Published:10 Feb 2005
    7.5
    High

    CVE-2005-0343

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in PerlDesk 1.x allows remote attackers to inject arbitrary SQL commands via the view parameter.

    Source:deluxe89
    Published:10 Feb 2005
    2.1
    Low

    CVE-2005-0342

    Last Modified: 6 Sept 2016

    The Finder in Mac OS X and earlier allows local users to overwrite arbitrary files and gain privileges by creating a hard link from the .DS_Store file to an arbitrary file.

    Source:vade79
    Published:10 Feb 2005
    5
    Medium

    CVE-2005-0340

    Last Modified: 16 Apr 2026

    Integer signedness error in Apple File Service (AFP Server) allows remote attackers to cause a denial of service (application crash) via a negative UAM string length in a FPLoginExt packet.

    Source:nemo
    Published:10 Feb 2005
    10
    Critical

    CVE-2005-0339

    Last Modified: 16 Apr 2026

    Buffer overflow in Foxmail 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long MAIL FROM command.

    Source:OYXin
    Published:10 Feb 2005
    7.5
    High

    CVE-2005-0338

    Last Modified: 27 Oct 2016

    Buffer overflow in Savant Web Server 3.1 allows remote attackers to execute arbitrary code via a long HTTP request.

    Source:Jerome Athias
    Published:10 Feb 2005