Skip to main content

Year archive

CVEs published in 2005

Archive summary

4,932 CVEs published in 2005 — 322 Critical, 1,739 High, 2,430 Medium, 441 Low, 0 Unrated.

CVE-2005-4819

Published Dec 31, 2005

Cross-site scripting (XSS) vulnerability in Lotus Domino versions before 6.5.4 fix pack 1 (FP1) and versions before 7.0 allows remote attackers to inject arbitrary web script or H…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4820

Published Dec 31, 2005

SMC Wireless Router model SMC7904WBRA allows remote attackers to cause a denial of service (reboot) by flooding the router with traffic.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4821

Published Dec 31, 2005

Multiple SQL injection vulnerabilities in Land Down Under (LDU) v801 and earlier allow remote attackers to execute arbitrary SQL commands via parameters including (1) the m parame…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4822

Published Dec 31, 2005

SQL injection vulnerability in projects/project-edit.asp in Digger Solutions Intranet Open Source (IOS) version 2.7.2 allows remote attackers to execute arbitrary SQL commands via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4823

Published Dec 31, 2005

Buffer overflow in the HP HTTP Server 5.0 through 5.95 of the HP Web-enabled Management Software allows remote attackers to execute arbitrary code via unknown vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-4824

Published Dec 31, 2005

PHP remote file inclusion vulnerability in web/classes.php in Siteframe before 3.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the LOCAL_PATH parameter, a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4826

Published Dec 31, 2005

Unspecified vulnerability in the VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(22)EA3 on Catalyst 2950T switches allows remote attackers to cause a denial of service (dev…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4828

Published Dec 31, 2005

Kolab Server 2.0.0 and 2.0.1 does not properly handle when a large email is sent with a "." in the wrong place, which causes kolabfilter to add another ".", which might break clea…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4829

Published Dec 31, 2005

VirtueMart before 1.0.1 does not properly handle errors when a user is forbidden to read a requested page, which has unknown impact and remote attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-4830

Published Dec 31, 2005

CRLF injection vulnerability in viewcvs in ViewCVS 0.9.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4831

Published Dec 31, 2005

viewcvs in ViewCVS 0.9.2 allows remote attackers to set the Content-Type header to arbitrary values via the content-type parameter, which can be leveraged for cross-site scripting…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4832

Published Dec 31, 2005

SQL injection vulnerability in the Oracle Database Server 10g allows remote authenticated users to execute arbitrary SQL commands with elevated privileges via the SUBSCRIPTION_NAM…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4833

Published Dec 31, 2005

IBM WebSphere Application Server (WAS) 6.0 before 20050201, when serving pages in an Application WAR or an Extended Document Root, allows remote attackers to obtain the JSP source…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4834

Published Dec 31, 2005

IBM WebSphere Application Server (WAS) 5.0.2.5 through 5.1.1.3 allows remote attackers to obtain JSP source code and other sensitive information, related to incorrect request proc…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4835

Published Dec 31, 2005

The ath_rate_sample function in the ath_rate/sample/sample.c sample code in MadWifi before 0.9.3 allows remote attackers to cause a denial of service (failed KASSERT and system cr…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4836

Published Dec 31, 2005

The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remote attackers to read JSP source…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4838

Published Dec 31, 2005

Multiple cross-site scripting (XSS) vulnerabilities in the example web applications for Jakarta Tomcat 5.5.6 and earlier allow remote attackers to inject arbitrary web script or H…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4839

Published Dec 31, 2005

PureTLS before 0.9b5 does not clear optional Extensions and Algorithm.Parameters values before parsing, which might trigger an information leak of values from earlier certificates.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4841

Published Dec 31, 2005

The Outlook Progress Ctl control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4842

Published Dec 31, 2005

The System Monitor Source Properties control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with t…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4843

Published Dec 31, 2005

The SmartConnect Class control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's C…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 326-350 of 4,932 CVEsPage 14 of 198