Skip to main content

Year archive

CVEs published in 2005

Archive summary

4,932 CVEs published in 2005 — 322 Critical, 1,739 High, 2,430 Medium, 441 Low, 0 Unrated.

CVE-2005-4869

Published Dec 31, 2005

The (1) to_char and (2) to_date function in IBM DB2 8.1 allows local users to cause a denial of service (application crash) via an empty string in the second parameter, which caus…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-4870

Published Dec 31, 2005

Stack-based buffer overflows in the (1) xmlvarcharfromfile, (2) xmlclobfromfile, (3) xmlfilefromvarchar, and (4) xmlfilefromclob function calls in IBM DB2 8.1 allow remote attacke…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4871

Published Dec 31, 2005

Certain XML functions in IBM DB2 8.1 run with the privileges of DB2 instead of the logged-in user, which allows remote attackers to create or overwrite files via (1) XMLFileFromVa…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4872

Published Dec 31, 2005

Perl-Compatible Regular Expression (PCRE) library before 6.2 does not properly count the number of named capturing subpatterns, which allows context-dependent attackers to cause a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4873

Published Dec 31, 2005

Multiple stack-based buffer overflows in the phpcups PHP module for CUPS 1.1.23rc1 might allow context-dependent attackers to execute arbitrary code via vectors that result in lon…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4874

Published Dec 31, 2005

The XMLHttpRequest object in Mozilla 1.7.8 supports the HTTP TRACE method, which allows remote attackers to obtain (1) proxy authentication passwords via a request with a "Max-For…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4875

Published Dec 31, 2005

TYPO3 3.8.0 and earlier allows remote attackers to obtain sensitive information via a direct request to misc/phpcheck/, which invokes the phpinfo function and prints values of uns…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4876

Published Dec 31, 2005

Cross-site scripting (XSS) vulnerability in the login form (login.jsp) of the admin console in Openfire (formerly Wildfire) 2.2.2, and possibly other versions before 2.3.0 Beta 2,…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4877

Published Dec 31, 2005

Cross-site scripting (XSS) vulnerability in the login form (login.jsp) of the admin console in Openfire (formerly Wildfire) 2.3.0 Beta 2 allows remote attackers to inject arbitrar…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4586

Published Dec 30, 2005

Multiple SQL injection vulnerabilities in PHPSurveyor before 0.991 allow remote attackers to execute arbitrary SQL commands via the (1) sql parameter in browse.php and the (2) sid…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4587

Published Dec 30, 2005

Juniper NetScreen-Security Manager (NSM) 2004 FP2 and FP3 allow remote attackers to cause a denial of service (crash or hang of server components that are automatically restarted)…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4588

Published Dec 30, 2005

Cross-site scripting (XSS) vulnerability in Koobi 5 allows remote attackers to inject arbitrary web script or HTML via nested, malformed url BBCode tags. NOTE: the provenance of…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4589

Published Dec 30, 2005

Spb Kiosk Engine 1.0.0.1 stores the administrator's passcode in the registry in plaintext, which allows local users to obtain the passcode.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-4590

Published Dec 30, 2005

Spb Kiosk Engine 1.0.0.1 allows local users to bypass restrictions on allowed applications via (1) removable media containing a program that will execute because of the autorun se…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4563

Published Dec 29, 2005

SQL injection vulnerability in main.php in Enterprise Heart Enterprise Connector 1.0.2 allows remote attackers to execute arbitrary SQL commands and bypass login authentication vi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4564

Published Dec 29, 2005

The Internet Key Exchange version 1 (IKEv1) implementation in ADTRAN NetVanta before 10.03.03.E might allow remote attackers to cause a denial of service via crafted IKE packets,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4565

Published Dec 29, 2005

Format string vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation in ADTRAN NetVanta before 10.03.03.E might allow remote attackers to have an unknown impa…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-4566

Published Dec 29, 2005

Buffer overflow in the Internet Key Exchange version 1 (IKEv1) implementation in ADTRAN NetVanta before 10.03.03.E might allow remote attackers to have an unknown impact via craft…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-4567

Published Dec 29, 2005

Multiple cross-site scripting (XSS) vulnerabilities in FTGate Technology (formerly known as Floosietek) FTGate 4.4 (Build 4.4.000 Oct 26 2005) allow remote attackers to inject arb…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4568

Published Dec 29, 2005

Multiple format string vulnerabilities in FTGate Technology (formerly known as Floosietek) FTGate 4.4 (aka Build 4.4.000 Oct 26 2005) allow remote attackers to execute arbitrary c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4569

Published Dec 29, 2005

Stack-based buffer overflow in index.fts in FTGate Technology (formerly known as Floosietek) FTGate 4.4 (aka Build 4.4.000 Oct 26 2005) allows remote attackers to execute arbitrar…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4571

Published Dec 29, 2005

Cross-site scripting (XSS) vulnerability in myEZshop Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the Keyword parameter. NOTE: the provenance…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4572

Published Dec 29, 2005

Multiple SQL injection vulnerabilities in myEZshop Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) GroupsId and (2) ItemsId parameters in admin.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4573

Published Dec 29, 2005

PHP remote file include vulnerability in plog-admin-functions.php in Plogger Beta 2 allows remote attackers to execute arbitrary code via a URL in the config[basedir] parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 376-400 of 4,932 CVEsPage 16 of 198