Skip to main content

Year archive

CVEs published in 2005

Archive summary

4,932 CVEs published in 2005 — 322 Critical, 1,739 High, 2,430 Medium, 441 Low, 0 Unrated.

CVE-2005-0249

Published Feb 8, 2005

Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative v…

CVSS 7.5 · High

CVE-2004-1131

Published Feb 7, 2005

Multiple buffer overflows in the enable command for SCO OpenServer 5.0.6 and 5.0.7 allow local users to execute arbitrary code via long command line arguments.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0100

Published Feb 7, 2005

Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0174

Published Feb 7, 2005

Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Co…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0175

Published Feb 7, 2005

Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0231

Published Feb 7, 2005

Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0226

Published Feb 3, 2005

Format string vulnerability in the Log_Resolver function in log.c for ngIRCd 0.8.2 and earlier, when compiled with IDENT, logging to SYSLOG, and with DEBUG enabled, allows remote…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0152

Published Feb 2, 2005

PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via "URL manipulation."

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0101

Published Feb 1, 2005

Buffer overflow in the socket_getline function in Newspost 2.1.1 and earlier allows remote malicious NNTP servers to execute arbitrary code via a long string without a newline cha…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0245

Published Feb 1, 2005

Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments to a refcursor function (gram.y), which le…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0224

Published Jan 31, 2005

Unknown vulnerability in HP-UX B.11.04 running Virtualvault 4.5 through 4.7, when running the TGA daemon, allows remote attackers to cause a denial of service via certain network…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0075

Published Jan 29, 2005

prefs.php in SquirrelMail before 1.4.4, with register_globals enabled, allows remote attackers to inject local code into the SquirrelMail code via custom preference handlers.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0104

Published Jan 29, 2005

Cross-site scripting (XSS) vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to inject arbitrary web script or HTML via certain integer variables.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0316

Published Jan 28, 2005

WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which could allow remote attackers to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0317

Published Jan 28, 2005

Cross-site scripting (XSS) vulnerability in useredit_account.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the user parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0318

Published Jan 28, 2005

useredit_account.wdm in Alt-N WebAdmin 3.0.4 does not properly validate account edits by the logged in user, which allows remote authenticated users to edit other users' account i…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0319

Published Jan 28, 2005

Direct remote injection vulnerability in modalfram.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to load external webpages that appear to come from the WebAdmin server, whic…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0320

Published Jan 28, 2005

Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) user…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0884

Published Jan 27, 2005

The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available SASL plug-ins, which allows local users…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0886

Published Jan 27, 2005

Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect mal…

CVSS 5.0 · Medium
Showing 4,601-4,625 of 4,932 CVEsPage 185 of 198