Skip to main content

Year archive

CVEs published in 2005

Archive summary

4,932 CVEs published in 2005 — 322 Critical, 1,739 High, 2,430 Medium, 441 Low, 0 Unrated.

CVE-2005-4844

Published Dec 31, 2005

The CLSID_ApprenticeICW control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4845

Published Dec 31, 2005

The Java Plug-in 1.4.2_03 and 1.4.2_04 controls, and the 1.4.2_03 and 1.4.2_04 <applet> redirector controls, allow remote attackers to cause a denial of service (Internet Explorer…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4846

Published Dec 31, 2005

Format string vulnerability in Logger.cc for Spey 0.3.3 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4847

Published Dec 31, 2005

Unspecified vulnerability in Spey 0.3.3 has unknown impact and attack vectors related to "A number of security holes which could lead to compromise," a different issue than CVE-20…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-4848

Published Dec 31, 2005

Buffer overflow in the decompression algorithm in Research in Motion BlackBerry Enterprise Server 4.0 SP1 and earlier before 20050607 might allow remote attackers to execute arbit…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4849

Published Dec 31, 2005

Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b) the output of the DatabaseMet…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4850

Published Dec 31, 2005

eZ publish 3.5 through 3.7 before 20050608 requires both edit and create permissions in order to submit data, which allows remote attackers to edit data submitted by arbitrary ano…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4851

Published Dec 31, 2005

eZ publish 3.4.4 through 3.7 before 20050722 applies certain permissions on the node level, which allows remote authenticated users to bypass the original permissions on embedded…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4852

Published Dec 31, 2005

The siteaccess URIMatching implementation in eZ publish 3.5 through 3.8 before 20050812 converts all non-alphanumeric characters in a URI to '_' (underscore), which allows remote…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4853

Published Dec 31, 2005

The default configuration of the forum package in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050818 does not restrict edit permissions to…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-4854

Published Dec 31, 2005

eZ publish 3.5 through 3.7 before 20050830 does not use a folder's read permissions to restrict notifications, which allows remote authenticated users to obtain sensitive informat…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4855

Published Dec 31, 2005

Unrestricted file upload vulnerability in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050922 does not restrict Image datatype uploads to i…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-4856

Published Dec 31, 2005

The admin interface in eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051110 does not properly handle authorization errors, which allows remote…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4857

Published Dec 31, 2005

eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051128 allows remote authenticated users to cause a denial of service (Apache httpd segmentation…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4858

Published Dec 31, 2005

Multiple cross-site scripting (XSS) vulnerabilities in mimic2.cgi in mimicboard2 (Mimic2) 086 and earlier allow remote attackers to inject arbitrary web script or HTML via unspeci…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4859

Published Dec 31, 2005

mimicboard2 (Mimic2) 086 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a d…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4860

Published Dec 31, 2005

Spectrum Cash Receipting System before 6.504 uses weak cryptography (static substitution) in the PASSFILE password file, which makes it easier for local users to gain privileges b…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4861

Published Dec 31, 2005

functions.php in Ragnarok Online Control Panel (ROCP) 4.3.4a allows remote attackers to bypass authentication by requesting account_manage.php with a trailing "/login.php" PHP_SEL…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4862

Published Dec 31, 2005

The search functionality in XWiki 0.9.793 indexes cleartext user passwords, which allows remote attackers to obtain sensitive information via a search string that matches a passwo…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4863

Published Dec 31, 2005

Stack-based buffer overflow in db2fmp in IBM DB2 7.x and 8.1 allows local users to execute arbitrary code via a long parameter.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4864

Published Dec 31, 2005

Stack-based buffer overflow in libdb2.so in IBM DB2 7.x and 8.1 allows local users to execute arbitrary code via a long DB2LPORT environment variable.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4865

Published Dec 31, 2005

Stack-based buffer overflow in call in IBM DB2 7.x and 8.1 allows remote attackers to execute arbitrary code via a long libname.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-4866

Published Dec 31, 2005

Stack-based buffer overflow in JDBC Applet Server in IBM DB2 8.1 allows remote attackers to execute arbitrary by connecting and sending a long username, then disconnecting gracefu…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4867

Published Dec 31, 2005

Stack-based buffer overflow in the SATENCRYPT function in IBM DB2 8.1, when Satellite Administration (SATADMIN) is enabled, allows remote attackers to execute arbitrary code via a…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 351-375 of 4,932 CVEsPage 15 of 198