Skip to main content

Year archive

CVEs published in 2005

Archive summary

4,932 CVEs published in 2005 — 322 Critical, 1,739 High, 2,430 Medium, 441 Low, 0 Unrated.

CVE-2005-0518

Published Feb 23, 2005

eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local users to gain privileges via the proxy_user and proxy_password…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0520

Published Feb 23, 2005

ArGoSoft FTP Server before 1.4.2.8 allows remote attackers to read arbitrary files via shortcut (.LNK) files in the SITE COPY command, a different vulnerability than CVE-2005-0519.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-0521

Published Feb 23, 2005

SendLink 1.5 stores sensitive information, possibly including passwords, in plaintext in the data.eat file, which allows local users to gain privileges.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0160

Published Feb 22, 2005

Multiple buffer overflows in unace 1.2b allow attackers to execute arbitrary code via (1) 2 overflows in ACE archives, (2) a long command line argument, or (3) certain "Ready for…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0161

Published Feb 22, 2005

Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archive containing (1) ../ sequences or (2) absolute pathnames.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0514

Published Feb 22, 2005

Cross-site scripting (XSS) vulnerability in Verity Ultraseek before 5.3.3 allows remote attackers to inject arbitrary HTML and web script via search parameters.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0535

Published Feb 22, 2005

Cross-site request forgery (CSRF) vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to perform unauthorized actions as authenticat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0937

Published Feb 22, 2005

Some futex functions in futex.c for Linux kernel 2.6.x perform get_user calls while holding the mmap_sem semaphore, which could allow local users to cause a deadlock condition in…

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0467

Published Feb 21, 2005

Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibly earlier versions, allow remo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0494

Published Feb 21, 2005

The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly validate the password before performing ch…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0496

Published Feb 21, 2005

Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the file system and possibly execut…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-0503

Published Feb 21, 2005

uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0511

Published Feb 21, 2005

misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0512

Published Feb 21, 2005

PHP remote file inclusion vulnerability in Tar.php in Mambo 4.5.2 allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to refer…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0537

Published Feb 21, 2005

Multiple SQL injection vulnerabilities in page.php for iGeneric (iG) Shop 1.2 may allow remote attackers to execute arbitrary SQL statements via the (1) cats, (2) l_price, or (3)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0499

Published Feb 20, 2005

Gigafast router (aka CompUSA router) with the DNS proxy option enabled allows remote attackers to cause a denial of service via malformed DNS queries.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0495

Published Feb 19, 2005

Cross-site scripting (XSS) vulnerability in ZeroBoard allows remote attackers to inject arbitrary web script or HTML via the (1) sn1, (2) year, or (3) page parameter to zboard.php…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0513

Published Feb 19, 2005

PHP remote file inclusion vulnerability in mail_autocheck.php in the Email This Entry add-on for pMachine Pro 2.4, and possibly other versions including pMachine Free, allows remo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0242

Published Feb 18, 2005

The Audio Setup Wizard (asw.dll) in Yahoo! Messenger 6.0.0.1750, and possibly other versions, allows attackers to arbitrary code by placing a malicious ping.exe program into the M…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0502

Published Feb 18, 2005

Directory traversal vulnerability in Xinkaa 1.0.3 and earlier allows remote attackers to read arbitrary files via (1) ../ and (2) ..\ characters in an HTTP request.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0519

Published Feb 18, 2005

ArGoSoft FTP Server before 1.4.2.7 allows remote attackers to read arbitrary files by uploading a ZIP file containing a shortcut (.LNK) file, using SITE UNZIP to extract the .LNK…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-0243

Published Feb 17, 2005

Yahoo! Messenger 6.0.0.1750, and possibly other versions before 6.0.0.1921, does not properly display long filenames in file dialog boxes, which could allow remote attackers to tr…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0462

Published Feb 17, 2005

Cross-site scripting (XSS) vulnerability in MercuryBoard 1.0.x and 1.1.x allows remote attackers to inject arbitrary HTML and web script via the f parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0105

Published Feb 16, 2005

Unknown vulnerability in typespeed 0.4.1 and earlier allows local users to gain privileges.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 4,526-4,550 of 4,932 CVEsPage 182 of 198