2005 CVE Vulnerabilities

4,770 CVEs published in 2005.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2005-2418——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-2403. Reason: This candidate is a duplicate of...
CVE-2005-2437——Website Baker Project does not properly verify the file extensions of uploaded files, which allows remote attackers to u...
CVE-2005-2449——Race condition in sandbox before 1.2.11 allows local users to create or overwrite arbitrary files via symlink attack on ...
CVE-2005-2436——browse.php in Website Baker Project allows remote attackers to obtain sensitive data via (1) a directory that does not e...
CVE-2005-2432——SQL injection vulnerability in PhpList allows remote attackers to modify SQL statements via the id argument to admin pag...
CVE-2005-2416——Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary ...
CVE-2005-2428——Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hid...
CVE-2005-2441——Multiple cross-site scripting (XSS) vulnerabilities in VBzoom allow remote attackers to inject arbitrary web script and ...
CVE-2005-2413——PHP remote file inclusion vulnerability in apa_phpinclude.inc.php in Atomic Photo Album (APA) allows remote attackers to...
CVE-2005-2427——Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ allows remote attackers to inject arbitrary web scri...
CVE-2005-2440——SQL injection vulnerability in login.asp in Thomson Web Skill Vantage Manager allows remote attackers to execute arbitra...
CVE-2005-2412——PHP remote file inclusion vulnerability in block.php in PHP FirstPost allows remote attackers to execute arbitrary PHP c...
CVE-2005-2445——SQL injection vulnerability in viewPrd.asp in Product Cart 2.6 allows remote attackers to execute arbitrary SQL commands...
CVE-2005-2448——Multiple "endianness errors" in libgadu in ekg before 1.6rc2 allow remote attackers to cause a denial of service (invali...
CVE-2005-2417——Contrexx before 1.0.5 allows remote attackers to obtain sensitive information via a direct request to /config/version.xm...
CVE-2005-2433——PhpList allows remote attackers to obtain sensitive information via a direct request to (1) about.php, (2) connect.php, ...
CVE-2005-2450——Multiple integer overflows in the (1) TNEF, (2) CHM, or (3) FSG file format processors in libclamav for Clam AntiVirus (...
CVE-2005-2451——Cisco IOS 12.0 through 12.4 and IOS XR before 3.2, with IPv6 enabled, allows remote attackers on a local network segment...
CVE-2005-2434——Linksys WRT54G router uses the same private key and certificate for every router, which allows remote attackers to sniff...
CVE-2005-2452——libtiff up to 3.7.0 allows remote attackers to cause a denial of service (application crash) via a TIFF image header wit...
CVE-2005-2446——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-2369. Reason: This candidate is a duplicate of...
CVE-2005-2346——Buffer overflow in Novell GroupWise 6.5 Client allows remote attackers to execute arbitrary code via a GWVW02xx.INI lang...
CVE-2005-2447——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-2370. Reason: This candidate is a duplicate of...
CVE-2005-1853——gopher.c in the Gopher client 3.0.5 does not properly create temporary files, which allows local users to gain privilege...
CVE-2005-2424——The management interface for Siemens SANTIS 50 running firmware 4.2.8.0, and possibly other products including Ericsson ...

Check if your code is affected by 2005 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now