2.1
    Low

    CVE-2005-0330

    Last Modified: 16 Apr 2026

    Buffer overflow in Painkiller 1.35 and earlier, and possibly other versions before 1.61, allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via a long cd-key hash.

    Source:Luigi Auriemma
    Published:10 Feb 2005
    5
    Medium

    CVE-2005-0325

    Last Modified: 16 Apr 2026

    Xpand Rally 1.0.0.0 allows remote attackers or remote malicious game servers to cause a denial of service (application crash) via a packet with large values that are not properly handled in certain malloc or memcpy operations.

    Source:Luigi Auriemma
    Published:10 Feb 2005
    5
    Medium

    CVE-2005-0320

    Last Modified: 29 Apr 2013

    Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to login.html, (2) accountid parameter to accountsettings_add.html, or the (3) note, (4) title, and (5) location fields to calendar.html.

    Source:ShineShadow
    Published:28 Jan 2005
    7.5
    High

    CVE-2005-0316

    Last Modified: 29 Apr 2013

    WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which could allow remote attackers to bypass intended access restrictions.

    Source:Oliver Karow
    Published:28 Jan 2005
    7.5
    High

    CVE-2005-0313

    Last Modified: 28 Apr 2013

    Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload arbitrary files via certain parameters to upload.php or (2) read arbitrary files via certain parameters to download.php, and remote authenticated users to read, create, or delete arbitrary directories and files via the IMAP commands (3) CREATE, (4) EXAMINE, (5) SELECT, or (6) DELETE.

    Source:Tan Chew Keong
    Published:27 Jan 2005
    2.1
    Low

    CVE-2005-0312

    Last Modified: 28 Apr 2013

    WarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access violation) via a CWD command with a crafted pathname, as demonstrated using a large string of "%s" sequences, possibly indicating a format string vulnerability.

    Source:MC.Iglo
    Published:27 Jan 2005
    7.5
    High

    CVE-2005-0308

    Last Modified: 10 Mar 2011

    Buffer overflow in the wsprintf function in W32Dasm 8.93 and earlier allows remote attackers to execute arbitrary code via a large import or export function name.

    Source:Metasploit
    Published:24 Jan 2005
    4.3
    Medium

    CVE-2005-0307

    Last Modified: 28 Apr 2013

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in MercuryBoard 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) s, (2) l, (3) a, (4) t, (5) to, or (6) re parameters.

    Source:Alberto Trivero
    Published:25 Jan 2005
    7.5
    High

    CVE-2005-0305

    Last Modified: 28 Apr 2013

    CRLF injection vulnerability in users.php in Siteman 1.1.10 and earlier allows remote attackers to add arbitrary users and gain privileges via the line parameter in a docreate operation.

    Source:Noam Rathaus
    Published:10 Feb 2005
    5
    Medium

    CVE-2005-0283

    Last Modified: 21 Apr 2016

    Directory traversal vulnerability in index.php in QwikiWiki allows remote attackers to read arbitrary files via a .. (dot dot) and a %00 at the end of the filename in the page parameter.

    Source:Madelman
    Published:4 Jan 2005
    7.5
    High

    CVE-2005-0280

    Last Modified: 16 Apr 2026

    Format string vulnerability in Soldner Secret Wars 30830 and earlier allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in a message.

    Source:Luigi Auriemma
    Published:4 Jan 2005
    5
    Medium

    CVE-2005-0277

    Last Modified: 27 Oct 2016

    Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via (1) a long username in the USER command or (2) an FTP command that contains a long argument, such as cd, send, or ls.

    Source:Metasploit
    Published:10 Feb 2005
    4.3
    Medium

    CVE-2005-0274

    Last Modified: 19 Jan 2018

    Multiple cross-site scripting (XSS) vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) si, (3) page, or (4) ppuser parameters.

    Source:GulfTech Security
    Published:3 Jan 2005
    7.5
    High

    CVE-2005-0273

    Last Modified: 19 Jan 2018

    Multiple SQL injection vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) ppuser parameter.

    Source:GulfTech Security
    Published:10 Feb 2005
    7.5
    High

    CVE-2005-0272

    Last Modified: 19 Jan 2018

    ReviewPost PHP Pro before 2.84 allows remote attackers to upload and execute arbitrary PHP files by posting a review file with multiple extensions, which bypasses the intended restrictions.

    Source:GulfTech Security
    Published:10 Feb 2005
    7.5
    High

    CVE-2005-0271

    Last Modified: 19 Jan 2018

    Multiple SQL injection vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to showcat.php or (2) product parameter to addfav.php.

    Source:GulfTech Security
    Published:3 Jan 2005
    4.3
    Medium

    CVE-2005-0270

    Last Modified: 19 Jan 2018

    Multiple cross-site scripting (XSS) vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to inject arbitrary web script or HTML via the (1) si parameter to showcat.php, (2) cat or (3) page parameter to showproduct.php, or (4) report parameter to reportproduct.php.

    Source:GulfTech Security
    Published:10 Feb 2005
    7.2
    High

    CVE-2005-0263

    Last Modified: 16 Apr 2026

    Buffer overflow in netpmon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -O argument.

    Source:intropy
    Published:10 Feb 2005
    7.2
    High

    CVE-2005-0262

    Last Modified: 16 Apr 2026

    Buffer overflow in ipl_varyon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -d argument.

    Source:intropy
    Published:10 Feb 2005
    10
    Critical

    CVE-2005-0260

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the Discovery Service for BrightStor ARCserve Backup 11.1 and earlier allows remote attackers to execute arbitrary code via a long packet to UDP port 41524, which is not properly handled in a recvfrom call.

    Source:Metasploit
    Published:10 Feb 2005
    5
    Medium

    CVE-2005-0256

    Last Modified: 28 Apr 2016

    The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir command.

    Source:str0ke
    Published:25 Feb 2005
    4
    Medium

    CVE-2005-0253

    Last Modified: 1 May 2013

    Directory traversal vulnerability in index.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to delete arbitrary files via a Delete action and .. (dot dot) sequences in the database_name parameter.

    Source:Patrick Hof
    Published:17 Feb 2005
    7.5
    High

    CVE-2005-0252

    Last Modified: 1 May 2013

    SQL injection vulnerability in BibORB 1.3.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the (1) Username or (2) Password.

    Source:Patrick Hof
    Published:17 Feb 2005
    4.3
    Medium

    CVE-2005-0251

    Last Modified: 1 May 2013

    Cross-site scripting (XSS) vulnerability in bibindex.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to inject arbitrary HTML and web script via the search parameter.

    Source:Patrick Hof
    Published:17 Feb 2005
    7.5
    High

    CVE-2005-0245

    Last Modified: 29 Apr 2013

    Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments to a refcursor function (gram.y), which leads to a heap-based buffer overflow, a different vulnerability than CVE-2005-0247.

    Source:ChoiX
    Published:20 Jan 2005
    5
    Medium

    CVE-2005-0229

    Last Modified: 29 Apr 2013

    CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote attackers to steal credit card information via a direct request to newfile.txt.

    Source:Maximillian Dornseif
    Published:14 Feb 2005
    7.5
    High

    CVE-2005-0226

    Last Modified: 21 Apr 2016

    Format string vulnerability in the Log_Resolver function in log.c for ngIRCd 0.8.2 and earlier, when compiled with IDENT, logging to SYSLOG, and with DEBUG enabled, allows remote attackers to execute arbitrary code.

    Source:CoKi
    Published:3 Feb 2005
    9.8
    Critical

    CVE-2005-0199

    Last Modified: 29 Apr 2013

    Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long MODE line that causes an incorrect length calculation, which leads to a buffer overflow.

    Source:Florian Westphal
    Published:6 Feb 2005
    7.2
    High

    CVE-2005-0193

    Last Modified: 22 Jun 2017

    Buffer overflow in the (1) -v and (2) -a switches in mRouter in iSync 1.5 in Mac OS X 10.3.7 and earlier allows local users to execute arbitrary code.

    Source:nemo
    Published:22 Jan 2005
    7.5
    High

    CVE-2005-0185

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in NodeManager Professional 2.00 allows remote attackers to execute arbitrary commands via a LinkDown-Trap packet that contains a long OCTET-STRING in the Trap variable-bindings field.

    Source:Tan Chew Keong
    Published:6 Feb 2005
    2.1
    Low

    CVE-2005-0161

    Last Modified: 6 May 2013

    Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archive containing (1) ../ sequences or (2) absolute pathnames.

    Source:Ulf Harnhammar
    Published:22 Feb 2005
    2.1
    Low

    CVE-2005-0156

    Last Modified: 16 Apr 2026

    Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.

    Source:Kevin Finisterre
    Published:1 Feb 2005
    4.6
    Medium

    CVE-2005-0155

    Last Modified: 21 Sept 2016

    The PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to create arbitrary files via the PERLIO_DEBUG variable.

    Source:Kevin Finisterre
    Published:1 Feb 2005
    Unknown

    CVE-2005-0153

    https://www.exploit-db.com/exploits/25080

    7.5
    High

    CVE-2005-0129

    Last Modified: 28 Apr 2013

    The Quick Buttons feature in Konversation 0.15 allows remote attackers to execute certain IRC commands via a channel name containing "%" variables, which are recursively expanded by the Server::parseWildcards function when the Part Button is selected.

    Published:22 Jan 2005
    Low

    CVE-2005-0122

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-0975. Reason: This candidate is a duplicate of CVE-2005-0975. Notes: All CVE users should reference CVE-2005-0975 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:nemo
    Published:20 Jan 2005
    7.5
    High

    CVE-2005-0116

    Last Modified: 21 Apr 2016

    AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.

    Source:GHC
    Published:18 Jan 2005
    4.6
    Medium

    CVE-2005-0105

    Last Modified: 30 Apr 2013

    Unknown vulnerability in typespeed 0.4.1 and earlier allows local users to gain privileges.

    Source:Ulf Harnhammar
    Published:16 Feb 2005
    7.5
    High

    CVE-2005-0101

    Last Modified: 29 Apr 2013

    Buffer overflow in the socket_getline function in Newspost 2.1.1 and earlier allows remote malicious NNTP servers to execute arbitrary code via a long string without a newline character.

    Source:Niels Heinen
    Published:1 Feb 2005
    7.5
    High

    CVE-2005-0063

    Last Modified: 16 Apr 2026

    The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.

    Source:ZwelL
    Published:13 Apr 2005
    10
    Critical

    CVE-2005-0059

    Last Modified: 9 Mar 2011

    Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.

    Source:Metasploit
    Published:13 Apr 2005
    7.5
    High

    CVE-2005-0058

    Last Modified: 16 Apr 2026

    Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to elevate privileges or execute arbitrary code via a crafted message.

    Source:Cesar Cerrudo
    Published:10 Aug 2005
    7.5
    High

    CVE-2005-0053

    Last Modified: 24 Apr 2013

    Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."

    Source:http-equiv
    Published:8 Feb 2005
    7.5
    High

    CVE-2005-0048

    Last Modified: 16 Apr 2026

    Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the "IP Validation Vulnerability."

    Source:Yuri Gushin
    Published:13 Apr 2005
    7.2
    High

    CVE-2005-0047

    Last Modified: 16 Apr 2026

    Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability."

    Source:Cesar Cerrudo
    Published:8 Feb 2005
    7.5
    High

    CVE-2005-0045

    Last Modified: 16 Apr 2026

    The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code via Transaction responses containing (1) Trans or (2) Trans2 commands, aka the "Server Message Block Vulnerability," and as demonstrated using Trans2 FIND_FIRST2 responses with large file name length fields.

    Source:cybertronic
    Published:8 Feb 2005
    7.5
    High

    CVE-2005-0043

    Last Modified: 16 Apr 2026

    Buffer overflow in Apple iTunes 4.7 allows remote attackers to execute arbitrary code via a long URL in (1) .m3u or (2) .pls playlist files.

    Source:nemo
    Published:19 Jan 2005
    2.1
    Low

    CVE-2005-0023

    Last Modified: 19 Jun 2013

    gnome-pty-helper in GNOME libzvt2 and libvte4 allows local users to spoof the logon hostname via a modified DISPLAY environment variable. NOTE: the severity of this issue has been disputed.

    Source:Paul Szabo
    Published:5 Oct 2005
    7.2
    High

    CVE-2005-0021

    Last Modified: 18 Dec 2018

    Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with more than 8 components, as demonstrated using the -be command line option, which triggers an overflow in the host_aton function, or (2) the -bh command line option or dnsdb PTR lookup, which triggers an overflow in the dns_build_reverse function.

    Source:Rafael Carrasco
    Published:4 Jan 2005
    Unknown

    CVE-2005-2

    https://github.com/kullai-secasure/CVE-2005-2x8x