Skip to main content

Year archive

CVEs published in 2005

Archive summary

4,932 CVEs published in 2005 — 322 Critical, 1,739 High, 2,430 Medium, 441 Low, 0 Unrated.

CVE-2005-0622

Published Mar 1, 2005

RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to view the PHP source code via an HTTP GET request for a filename with a trailing (1) . (do…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0623

Published Mar 1, 2005

Buffer overflow in RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to execute arbitrary code via a long URL.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0628

Published Mar 1, 2005

Multiple cross-site scripting (XSS) vulnerabilities in Forumwa 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter in search.php or the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0629

Published Mar 1, 2005

Multiple cross-site scripting (XSS) vulnerabilities in profile.php in 427BB 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) Avatar parame…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0630

Published Mar 1, 2005

sendpm.php in PBLang 4.63 allows remote authenticated users to read arbitrary files via a full pathname in the orig parameter.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0631

Published Mar 1, 2005

delpm.php in PBLang 4.63 allows remote authenticated users to delete arbitrary PM files by modifying the "id" and "a" parameters.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0632

Published Mar 1, 2005

PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP code via the path parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0945

Published Feb 28, 2005

The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 allows remote authenticated users to cause a denial of service (resource exhau…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0603

Published Feb 28, 2005

viewtopic.php in phpBB 2.0.12 and earlier allows remote attackers to obtain sensitive information via a highlight parameter containing invalid regular expression syntax, which rev…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0608

Published Feb 28, 2005

Heap-based buffer overflow in server.cpp for WebMod 0.47 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a POST request with a Content-…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0613

Published Feb 28, 2005

Unknown vulnerability in FCKeditor 2.0 RC2, when used with PHP-Nuke, allows remote attackers to upload arbitrary files.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0616

Published Feb 28, 2005

Multiple cross-site scripting (XSS) vulnerabilities in the Download module for PostNuke 0.750 and 0.760-RC2 allow remote attackers to inject arbitrary web script or HTML via the (…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0619

Published Feb 28, 2005

Einstein 1.0.1 stores sensitive information such as usernames and passwords in plaintext in the registry, which allows local users to gain privileges.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0624

Published Feb 28, 2005

reportbug before 2.62 creates the .reportbugrc configuration file with world-readable permissions, which allows local users to obtain email smarthost passwords.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0625

Published Feb 28, 2005

reportbug 3.2 includes settings from .reportbugrc in bug reports, which exposes sensitive information such as smtpuser and smtppasswd.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0107

Published Feb 25, 2005

bsmtpd 2.3 and earlier does not properly sanitize e-mail addresses, which allows remote attackers to execute arbitrary commands.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0579

Published Feb 25, 2005

nxagent in FreeNX before 0.2.8 does not properly handle when the XAUTHORITY environment variable is not set, which allows local users to access the X server without X authenticati…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0580

Published Feb 25, 2005

cmd5checkpw, when running setuid, does not properly drop privileges before calling the execvp function, which allows local users to read the poppasswd file.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0543

Published Feb 24, 2005

Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cfg[BgcolorOne], or strServerCh…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0547

Published Feb 24, 2005

Unknown vulnerability in ftpd on HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23 allows remote authenticated users to gain "unauthorized access to files."

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0481

Published Feb 23, 2005

The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary files via a symlink attack on th…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0516

Published Feb 23, 2005

The ImageGalleryPlugin (ImageGalleryPlugin.pm) in Twiki allows remote attackers to execute arbitrary commands via certain commands that generate thumbnails.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0517

Published Feb 23, 2005

PeerFTP_5 stores sensitive information such as passwords in plaintext in the PeerFTP.ini files, which allows local users to gain privileges.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 4,501-4,525 of 4,932 CVEsPage 181 of 198