Skip to main content

Year archive

CVEs published in 2005

Archive summary

4,932 CVEs published in 2005 — 322 Critical, 1,739 High, 2,430 Medium, 441 Low, 0 Unrated.

CVE-2005-4509

Published Dec 23, 2005

SQL injection vulnerability in index.asp in pTools allows remote attackers to execute arbitrary SQL commands via the docID parameter. NOTE: the provenance of this information is u…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4510

Published Dec 23, 2005

Directory traversal vulnerability in server.np in NetPublish Server 7 allows remote attackers to read arbitrary files via "../" sequences in the template parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4511

Published Dec 23, 2005

Format string vulnerability in TN3270 Resource Gateway 1.1.0 allows local users to cause a denial of service and possibly execute arbitrary code via format string specifiers in sy…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4512

Published Dec 23, 2005

Cross-site scripting (XSS) vulnerability in WAXTRAPP 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4513

Published Dec 23, 2005

Cross-site scripting (XSS) vulnerability in WANDSOFT e-SEARCH allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the keywor…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4514

Published Dec 23, 2005

The encapsulation script mechanism in Webwasher CSM Appliance Suite 5.x uses case-sensitive detection of malicious tokens, which allows attackers to bypass script detection by usi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4515

Published Dec 23, 2005

SQL injection vulnerability in WebDB 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified search parameters, possibly Search0. NOTE: the vend…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4506

Published Dec 23, 2005

Nexus Concepts Dev Hound 2.24 and earlier stores username and password information in cleartext in the devhound.tdbd file, which allows local users to gain privileges.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4507

Published Dec 23, 2005

Multiple cross-site scripting (XSS) vulnerabilities in Nexus Concepts Dev Hound 2.24 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple unspeci…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4508

Published Dec 23, 2005

Nexus Concepts Dev Hound 2.24 and earlier allows remote attackers to obtain the installation path via a URL containing a non-existent .dll file.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3536

Published Dec 22, 2005

SQL injection vulnerability in phpBB 2 before 2.0.18 allows remote attackers to execute arbitrary SQL commands via the topic type.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-3537

Published Dec 22, 2005

A "missing request validation" error in phpBB 2 before 2.0.18 allows remote attackers to edit private messages of other users, probably by modifying certain parameters or other in…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3660

Published Dec 22, 2005

Linux kernel 2.4 and 2.6 allows attackers to cause a denial of service (memory exhaustion and panic) by creating a large number of connected file descriptors or socketpairs and se…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3534

Published Dec 22, 2005

Buffer overflow in the Network Block Device (nbd) server 2.7.5 and earlier, and 2.8.0 through 2.8.2, allows remote attackers to execute arbitrary code via a large request, which i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4500

Published Dec 22, 2005

SQL injection vulnerability in MusicBox 2.3 allows remote attackers to execute arbitrary SQL commands via the (1) show and (2) type parameter. NOTE: the provenance of this inform…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4501

Published Dec 22, 2005

MediaWiki before 1.5.4 uses a hard-coded "internal placeholder string", which allows remote attackers to bypass protection against cross-site scripting (XSS) attacks and execute J…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4502

Published Dec 22, 2005

Cross-site scripting (XSS) vulnerability in httprint v202, and possibly other versions before v301, allows remote attackers to inject arbitrary web script or HTML via the Server f…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4503

Published Dec 22, 2005

httprint v202, and possibly other versions before v301, allows remote attackers to cause a denial of service (crash) via a long Server field in an HTTP response.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4475

Published Dec 22, 2005

Cross-site scripting (XSS) vulnerability in OpenCms 6.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4476

Published Dec 22, 2005

Cross-site scripting (XSS) vulnerability in store/search/results.html in OpenEdit 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) oe-act…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4477

Published Dec 22, 2005

Cross-site scripting (XSS) vulnerability in papaya CMS 4.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the bab[searchfor] parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4478

Published Dec 22, 2005

Multiple SQL injection vulnerabilities in Papoo 2.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) menuid parameter to (a) index.php and (b) gu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 451-475 of 4,932 CVEsPage 19 of 198