Skip to main content

Year archive

CVEs published in 2005

Archive summary

4,932 CVEs published in 2005 — 322 Critical, 1,739 High, 2,430 Medium, 441 Low, 0 Unrated.

CVE-2005-0452

Published Feb 16, 2005

Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or web script via Unicode repres…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0453

Published Feb 16, 2005

The buffer_urldecode function in Lighttpd 1.3.7 and earlier does not properly handle control characters, which allows remote attackers to obtain the source code for CGI and FastCG…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0149

Published Feb 15, 2005

Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers to bypass the us…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0176

Published Feb 15, 2005

The shmctl function in Linux 2.6.9 and earlier allows local users to unlock the memory of other processes, which could cause sensitive memory to be swapped to disk, which could al…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0433

Published Feb 15, 2005

Php-Nuke 7.5 allows remote attackers to determine the full path of the web server via invalid or missing arguments to (1) db.php, (2) mainfile.php, (3) Downloads/index.php, or (4)…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0434

Published Feb 15, 2005

Multiple cross-site scripting (XSS) vulnerabilities in Php-Nuke 7.5 allow remote attackers to inject arbitrary HTML or web script via (1) the newdownloadshowdays parameter in a Ne…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0447

Published Feb 15, 2005

Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (hang) via a flood of certain ARP packets.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0406

Published Feb 14, 2005

A design flaw in image processing software that modifies JPEG images might not modify the original EXIF thumbnail, which could lead to an information leak of potentially sensitive…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0408

Published Feb 14, 2005

CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to bypass authentication and gain privile…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-0409

Published Feb 14, 2005

CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensiti…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0410

Published Feb 14, 2005

SQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and earlier allows remote attackers to inject data via the fields of a CSV file.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0411

Published Feb 14, 2005

Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and local users to include arbitrary PHP files via .. (dot dot) sequences in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0444

Published Feb 14, 2005

VMware before 4.5.2.8848-r5 searches for gdk-pixbuf shared libraries using a path that includes the rrdharan world-writable temporary directory, which allows local users to execut…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0430

Published Feb 12, 2005

The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash the server via a long infostr…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0074

Published Feb 11, 2005

Buffer overflow in pcdsvgaview in xpcd 2.08 allows local users to execute arbitrary code.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0261

Published Feb 10, 2005

lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0364

Published Feb 10, 2005

Unknown vulnerability in BIND 9.2.0 in HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to cause a denial of service.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0939

Published Feb 9, 2005

changepassword.cgi in Neoteris Instant Virtual Extranet (IVE) 3.x and 4.x, with LDAP authentication or NT domain authentication enabled, does not limit the number of times a bad p…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0941

Published Feb 9, 2005

Multiple buffer overflows in the gd graphics library (libgd) 2.0.21 and earlier may allow remote attackers to execute arbitrary code via malformed image files that trigger the ove…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0942

Published Feb 9, 2005

Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines wit…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0950

Published Feb 9, 2005

NetOp Host before 7.65 build 2004278 allows remote attackers to obtain sensitive hostname, username and local IP address information via (1) a NetOp HELO request, or (2) when resp…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 4,551-4,575 of 4,932 CVEsPage 183 of 198