Skip to main content

Year archive

CVEs published in 2005

Archive summary

4,932 CVEs published in 2005 — 322 Critical, 1,739 High, 2,430 Medium, 441 Low, 0 Unrated.

CVE-2005-4467

Published Dec 22, 2005

Directory traversal vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to read and include arbitrary files via a .. (dot dot) in the PGV_B…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4468

Published Dec 22, 2005

PHP remote file include vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to execute arbitrary code via a URL in the PGV_BASE_DIRECTORY p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4469

Published Dec 22, 2005

Multiple direct static code injection vulnerabilities in PHPGedView 3.3.7 and earlier allow remote attackers to execute arbitrary PHP code via (1) the username field in login.php,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4470

Published Dec 22, 2005

Heap-based buffer overflow in the get_bhead function in readfile.c in Blender BlenLoader 2.0 through 2.40pre allows remote attackers to cause a denial of service (application cras…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4471

Published Dec 22, 2005

POP3 service in Avaya Modular Messaging Message Storage Server (MSS) 2.0 SP 4 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted packets.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4472

Published Dec 22, 2005

Stack-based buffer overflow in the Macromedia JRun 4 web server (JWS) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long request t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4473

Published Dec 22, 2005

Unspecified vulnerability in Macromedia JRun 4 web server (JWS) allows remote attackers to view web application source code via "a malformed URL."

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4462

Published Dec 21, 2005

PHP remote file include vulnerability in usermods.php in Tolva PHP website system 0.1.0 allows remote attackers to execute arbitrary code via a URL in the ROOT parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4463

Published Dec 21, 2005

WordPress before 1.5.2 allows remote attackers to obtain sensitive information via a direct request to (1) wp-includes/vars.php, (2) wp-content/plugins/hello.php, (3) wp-admin/upg…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4460

Published Dec 21, 2005

Cross-site scripting (XSS) vulnerability in Beehive Forum 0.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Description, and (…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4461

Published Dec 21, 2005

SQL injection vulnerability in index.php in Beehive Forum 0.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_sess parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4267

Published Dec 21, 2005

Stack-based buffer overflow in Qualcomm WorldMail 3.0 allows remote attackers to execute arbitrary code via a long IMAP command that ends with a "}" character, as demonstrated usi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4448

Published Dec 21, 2005

FlatNuke 2.5.6 verifies authentication credentials based on an MD5 checksum of the admin name and the hashed password rather than the plaintext password, which allows attackers to…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-4449

Published Dec 21, 2005

verify.php in FlatNuke 2.5.6 allows remote authenticated administrators to modify arbitrary PHP files by setting the file parameter to an arbitrary file and injecting the code int…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4450

Published Dec 21, 2005

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.7.0 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag to server_pri…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4451

Published Dec 21, 2005

Unspecified vulnerability in Software Distributor in HP-UX B.11.11 allows remote attackers to gain access via unspecified attack vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4452

Published Dec 21, 2005

Information Call Center stores the CallCenterData.mdb database under the web root with insufficient access control, which allows remote attackers to obtain sensitive information s…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4453

Published Dec 21, 2005

UserProfile.cs in Ultraapps Issue Manager before 2.1 allows remote authenticated users to gain administrator privileges by modifying the original (1) p_User_user_id and (2) User_u…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-4454

Published Dec 21, 2005

Validate-before-filter vulnerability in cleanhtml.pl 1.129 in LiveJournal CVS before Dec 7 2005, when the cleancss option is enabled, allows remote attackers to conduct cross-site…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4455

Published Dec 21, 2005

cleanhtml.pl 1.129 in LiveJournal CVS before Dec 13 2005 allows remote attackers to inject scripting languages via the XSL namespace in XML, via vectors such as customview.cgi.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4457

Published Dec 21, 2005

MailEnable Enterprise 1.1 before patch ME-10009 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via several "..." (triple dot) seq…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4458

Published Dec 21, 2005

Group.pm in Metadot Portal Server 6.4.4 and earlier does not properly reset the $IS_OWNER, $IS_ADMIN, and $IS_MANAGER global variables when performing checks for special privilege…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 501-525 of 4,932 CVEsPage 21 of 198