Skip to main content

Year archive

CVEs published in 2005

Archive summary

4,932 CVEs published in 2005 — 322 Critical, 1,739 High, 2,430 Medium, 441 Low, 0 Unrated.

CVE-2005-4440

Published Dec 21, 2005

The 802.1q VLAN protocol allows remote attackers to bypass network segmentation and spoof VLAN traffic via a message with two 802.1q tags, which causes the second tag to be redire…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4441

Published Dec 21, 2005

The PVLAN protocol allows remote attackers to bypass network segmentation and spoof PVLAN traffic via a PVLAN message with a target MAC address that is set to a gateway router, wh…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4442

Published Dec 21, 2005

Untrusted search path vulnerability in OpenLDAP before 2.2.28-r3 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Po…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4443

Published Dec 21, 2005

Untrusted search path vulnerability in Gauche before 0.8.6-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Porta…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4444

Published Dec 21, 2005

Stack-based buffer overflow in the trace message functionality in Pegasus Mail 4.21a through 4.21c and 4.30PB1 allow remote attackers to execute arbitrary code via a long POP3 rep…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4445

Published Dec 21, 2005

Off-by-one error in Pegasus Mail 4.21a through 4.21c and 4.30PB1 allows remote attackers to execute arbitrary code via a long email message header, which triggers a one-byte buffe…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4446

Published Dec 21, 2005

Cross-site scripting (XSS) vulnerability in index.asp in ASPBite 8.x allows remote attackers to inject arbitrary web script or HTML via the strSearch parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4447

Published Dec 21, 2005

SQL injection vulnerability in articles\articles_funcs.php in phpCOIN 1.2.2 allows remote attackers to modify SQL syntax and possibly execute SQL in limited circumstances via the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4434

Published Dec 21, 2005

Cross-site scripting (XSS) vulnerability in AbleDesign ReSearch 2.x allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of thi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4435

Published Dec 21, 2005

Cross-site scripting (XSS) vulnerability in index.php AbleDesign D-Man 3.x allows remote attackers to inject arbitrary web script or HTML via the title parameter. NOTE: the proven…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4438

Published Dec 21, 2005

Heap-based buffer overflow in Dec2Rar.dll 3.2.14.3, as distributed in the Symantec Antivirus Library and used by various Symantec products, allows remote attackers to execute arbi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4439

Published Dec 21, 2005

Buffer overflow in ELOG elogd 2.6.0-beta4 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a URL with a long (1) cm…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4348

Published Dec 21, 2005

fetchmail before 6.3.1 and before 6.2.5.5, when configured for multidrop mode, allows remote attackers to cause a denial of service (application crash) by sending messages without…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4429

Published Dec 21, 2005

SQL injection vulnerability in CS-Cart 1.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) sort_by and (2) sort_order parameters to index.php.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4430

Published Dec 21, 2005

SQL injection vulnerability in LogicBill 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) __mode and (2) __id parameters to helpdesk.php.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4431

Published Dec 21, 2005

SQL injection vulnerability in WowBB 1.65 allows remote attackers to execute arbitrary SQL commands via the q parameter to search.php. NOTE: the view_user.php/sort_by vector is al…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4432

Published Dec 21, 2005

Cross-site scripting (XSS) vulnerability in index.php in PlaySMS 0.8 allows remote attackers to inject arbitrary web script or HTML via the err parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4427

Published Dec 20, 2005

Multiple SQL injection vulnerabilities in Cerberus Helpdesk allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to attachment_send.php, (2) the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4428

Published Dec 20, 2005

Cross-site scripting (XSS) vulnerability in index.php in Cerberus Helpdesk allows remote attackers to inject arbitrary web script or HTML via the kb_ask parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4390

Published Dec 20, 2005

SQL injection vulnerability in index.php in ContentServ 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the StoryID parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4391

Published Dec 20, 2005

Cross-site scripting (XSS) vulnerability in damoon allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the q parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4392

Published Dec 20, 2005

SQL injection vulnerability in printer_friendly.cfm in e-publish CMS 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 526-550 of 4,932 CVEsPage 22 of 198