2005 CVE Vulnerabilities

4,770 CVEs published in 2005.

CVE IDSeverityCVSSDescription
CVE-2005-4853The default configuration of the forum package in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, an...
CVE-2005-4852The siteaccess URIMatching implementation in eZ publish 3.5 through 3.8 before 20050812 converts all non-alphanumeric ch...
CVE-2005-4851eZ publish 3.4.4 through 3.7 before 20050722 applies certain permissions on the node level, which allows remote authenti...
CVE-2005-4850eZ publish 3.5 through 3.7 before 20050608 requires both edit and create permissions in order to submit data, which allo...
CVE-2005-4849Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter ...
CVE-2005-4848Buffer overflow in the decompression algorithm in Research in Motion BlackBerry Enterprise Server 4.0 SP1 and earlier be...
CVE-2005-4847Unspecified vulnerability in Spey 0.3.3 has unknown impact and attack vectors related to "A number of security holes whi...
CVE-2005-4846Format string vulnerability in Logger.cc for Spey 0.3.3 allows attackers to cause a denial of service (crash) and possib...
CVE-2005-4845The Java Plug-in 1.4.2_03 and 1.4.2_04 controls, and the 1.4.2_03 and 1.4.2_04 <applet> redirector controls, allow remot...
CVE-2005-4844The CLSID_ApprenticeICW control allows remote attackers to cause a denial of service (Internet Explorer crash) by creati...
CVE-2005-4843The SmartConnect Class control allows remote attackers to cause a denial of service (Internet Explorer crash) by creatin...
CVE-2005-4842The System Monitor Source Properties control allows remote attackers to cause a denial of service (Internet Explorer cra...
CVE-2005-4841The Outlook Progress Ctl control allows remote attackers to cause a denial of service (Internet Explorer crash) by creat...
CVE-2005-4840The Outlook Express Address Book control, when using Internet Explorer 6, allows remote attackers to cause a denial of s...
CVE-2005-4839PureTLS before 0.9b5 does not clear optional Extensions and Algorithm.Parameters values before parsing, which might trig...
CVE-2005-4838Multiple cross-site scripting (XSS) vulnerabilities in the example web applications for Jakarta Tomcat 5.5.6 and earlier...
CVE-2005-4837snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in maste...
CVE-2005-4836The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is c...
CVE-2005-4835The ath_rate_sample function in the ath_rate/sample/sample.c sample code in MadWifi before 0.9.3 allows remote attackers...
CVE-2005-4834IBM WebSphere Application Server (WAS) 5.0.2.5 through 5.1.1.3 allows remote attackers to obtain JSP source code and oth...
CVE-2005-4833IBM WebSphere Application Server (WAS) 6.0 before 20050201, when serving pages in an Application WAR or an Extended Docu...
CVE-2005-4772liby2util in Yet another Setup Tool (YaST) in SUSE Linux before 20051007 preserves permissions and ownerships when copyi...
CVE-2005-4831viewcvs in ViewCVS 0.9.2 allows remote attackers to set the Content-Type header to arbitrary values via the content-type...
CVE-2005-4719Multiple SQL injection vulnerabilities in Sysbotz Systems Panel 1.0.6 and earlier allow remote attackers to execute arbi...
CVE-2005-4824PHP remote file inclusion vulnerability in web/classes.php in Siteframe before 3.2.2 allows remote attackers to execute ...

Check if your code is affected by 2005 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now