Skip to main content

Year archive

CVEs published in 2005

Archive summary

4,932 CVEs published in 2005 — 322 Critical, 1,739 High, 2,430 Medium, 441 Low, 0 Unrated.

CVE-2005-0701

Published Mar 7, 2005

Directory traversal vulnerability in Oracle Database Server 8i and 9i allows remote attackers to read or rename arbitrary files via "\\.\\.." (modified dot dot backslash) sequenc…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0702

Published Mar 7, 2005

SQL injection vulnerability in phpMyFAQ 1.4 and 1.5 allows remote attackers to add FAQ records to the database via the username field in forum messages.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0722

Published Mar 7, 2005

eXPerience2 allows remote attackers to obtain the full path for the web root via a direct request to modules.php without any parameters, which leaks the path in a PHP error messag…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0681

Published Mar 6, 2005

Nokia Symbian 60 allows remote attackers to cause a denial of service (phone restart) via a Bluetooth nickname.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0687

Published Mar 6, 2005

Format string vulnerability in Hashcash 1.16 allows remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via format string specif…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0691

Published Mar 6, 2005

PHP remote file inclusion vulnerability in article mode for modules.php in SocialMPN allows remote attackers to execute arbitrary PHP code by modifying the name parameter to refer…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0692

Published Mar 6, 2005

Cross-site scripting (XSS) vulnerability in fusion_core.php for PHP-Fusion 5.x allows remote attackers to inject arbitrary web script or HTML via a message with IMG bbcode contain…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0593

Published Mar 4, 2005

Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" lock icon via (1) a web site that does not finish loading, which shows the loc…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0671

Published Mar 3, 2005

Format string vulnerability in Carsten's 3D Engine (Ca3DE), March 2004 version and earlier, allows remote attackers to execute arbitrary code via format string specifiers in a com…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0674

Published Mar 3, 2005

Cross-site scripting (XSS) vulnerability in the News module for paBox 1.6 allows remote attackers to inject arbitrary web script or HTML via the text hidden parameter in an HTTP P…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0620

Published Mar 2, 2005

Einstein 1.0 stores credit card information in plaintext in the world-readable wallets.dat file, which allows local users to steal the information.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0636

Published Mar 2, 2005

Format string vulnerability in Foxmail Server 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the USER c…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-0638

Published Mar 2, 2005

xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly q…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0639

Published Mar 2, 2005

Multiple vulnerabilities in xli before 1.17 may allow remote attackers to execute arbitrary code via "buffer management errors" from certain image properties, some of which may be…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0640

Published Mar 2, 2005

Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 does not properly initialize the "Change Credentials for Database" window, which allows local users to recover the SQ…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0641

Published Mar 2, 2005

Cross-site scripting (XSS) vulnerability in the Reporter for Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 allows remote attackers to inject arbitrary HTML or web…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0988

Published Mar 1, 2005

Integer overflow on Apple QuickTime before 6.5.2, when running on Windows systems, allows remote attackers to cause a denial of service (memory consumption) via certain inputs tha…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 4,451-4,475 of 4,932 CVEsPage 179 of 198