Skip to main content

Year archive

CVEs published in 2005

Archive summary

4,932 CVEs published in 2005 — 322 Critical, 1,739 High, 2,430 Medium, 441 Low, 0 Unrated.

CVE-2005-4574

Published Dec 29, 2005

Cross-site scripting (XSS) vulnerability in loader.cfm in PaperThin CommonSpot Content Server 4.5 and earlier allows remote attackers to inject arbitrary web script or HTML via th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4575

Published Dec 29, 2005

PaperThin CommonSpot Content Server 4.5 and earlier allow remote attackers to obtain sensitive information via an invalid errmsg parameter to loader.cfm with a url parameter set t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4576

Published Dec 29, 2005

Multiple cross-site scripting (XSS) vulnerabilities in the UpdateEngine program in Fatwire UpdateEngine 6.2 and earlier allow remote attackers to inject arbitrary web script or HT…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4577

Published Dec 29, 2005

Multiple cross-site scripting (XSS) vulnerabilities in Hitachi Business Logic - Container (BLC) P-2443-9114 01-00 through 02-06 on Windows, and P-1M43-9111 01-01 through 02-00 on…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4578

Published Dec 29, 2005

Multiple SQL injection vulnerabilities in Hitachi Business Logic - Container (BLC) P-2443-9114 01-00 through 02-06 on Windows, and P-1M43-9111 01-01 through 02-00 on AIX, allow re…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4579

Published Dec 29, 2005

Multiple HTTP response splitting vulnerabilities in Hitachi Business Logic - Container (BLC) P-2443-9114 01-00 through 02-06 on Windows, and P-1M43-9111 01-01 through 02-00 on AIX…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4580

Published Dec 29, 2005

Cross-site scripting (XSS) vulnerability in Day Communique 4 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4581

Published Dec 29, 2005

Buffer overflow in Electric Sheep 2.6.3 client allows local users to execute arbitrary code via a long window-id parameter. NOTE: because the program is not setuid and not normall…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4582

Published Dec 29, 2005

Electric Sheep 2.6.3 does not require authentication or integrity checks from the server to the client, which allows remote attackers to download and display arbitrary MPEG movie…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4583

Published Dec 29, 2005

Unspecified vulnerability in the Management Interface in VMware ESX Server 2.x up to 2.5.x before 24 December 2005 allows "remote code execution in the Web browser" via unspecifie…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4584

Published Dec 29, 2005

BZFlag server 2.0.4 and earlier allows remote attackers to cause a denial of service (application crash) via a callsign that is not followed by a NULL (\0) character.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4585

Published Dec 29, 2005

Unspecified vulnerability in the GTP dissector for Ethereal 0.9.1 to 0.10.13 allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2005-3345

Published Dec 28, 2005

rssh 2.0.0 through 2.2.3 allows local users to bypass access restrictions and gain root privileges by using the rssh_chroot_helper command to chroot to an external directory.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4545

Published Dec 28, 2005

Cross-site scripting (XSS) vulnerability in search.asp in NetDirect ShopEngine allows remote attackers to inject arbitrary web script or HTML via the EXPS parameter. NOTE: the pro…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4546

Published Dec 28, 2005

search.php in eggblog 2.0 allows remote attackers to obtain the full path via an invalid q parameter, as used by the Keyword and Search fields, possibly due to an SQL injection vu…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4547

Published Dec 28, 2005

Cross-site scripting (XSS) vulnerability in home/search.php in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the q parameter, as used by the Keyword an…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4548

Published Dec 28, 2005

SQL injection vulnerability in the "user area" in RWS Statistics Counter before 2.4.1 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4549

Published Dec 28, 2005

Cross-site scripting (XSS) vulnerability in Oracle Application Server (OracleAS) Discussion Forum Portlet allows remote attackers to inject arbitrary web script or HTML via the (1…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4550

Published Dec 28, 2005

The PORTAL schema in Oracle Application Server (OracleAS) Discussion Forum Portlet allows remote attackers to obtain the source code for arbitrary JSP and other files via a df_nex…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4551

Published Dec 28, 2005

Cross-site scripting (XSS) vulnerability in sign.php in codegrrl SimpBook 1.0, when html_enable is on, allows remote attackers to inject arbitrary web script or HTML via the messa…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4552

Published Dec 28, 2005

The (1) slsmgr and (2) slsadmin programs in Sun Solaris PC NetLink 2.0 create temporary files insecurely, which allows local users to gain privileges.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4553

Published Dec 28, 2005

Buffer overflow in Golden FTP Server 1.92 allows remote attackers to execute arbitrary code via a long APPE command. NOTE: the provenance of this information is unknown; the deta…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4554

Published Dec 28, 2005

Multiple SQL injection vulnerabilities in DEV web management system 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter in an openfo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4555

Published Dec 28, 2005

Cross-site scripting (XSS) vulnerability in add.php in DEV web management system 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) ENTER_A…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 401-425 of 4,932 CVEsPage 17 of 198