2005 CVE Vulnerabilities

4,770 CVEs published in 2005.

CVE IDSeverityCVSSDescription
CVE-2005-2438——Cross-site scripting (XSS) vulnerability in UseBB 0.5.1 and earlier allows remote attackers to inject arbitrary Javascri...
CVE-2005-2437——Website Baker Project does not properly verify the file extensions of uploaded files, which allows remote attackers to u...
CVE-2005-2429——Firefox, when opening Microsoft Word documents, does not properly set the permissions on shared sections, which allows r...
CVE-2005-2425——Stack-based buffer overflow in Ares FileShare 1.1 allows remote attackers or local users to execute arbitrary code via a...
CVE-2005-2424——The management interface for Siemens SANTIS 50 running firmware 4.2.8.0, and possibly other products including Ericsson ...
CVE-2005-2428——Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hid...
CVE-2005-2427——Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ allows remote attackers to inject arbitrary web scri...
CVE-2005-2426——FTPshell Server 3.38 allows remote authenticated users to cause a denial of service (application crash) by multiple conn...
CVE-2005-2436——browse.php in Website Baker Project allows remote attackers to obtain sensitive data via (1) a directory that does not e...
CVE-2005-2434——Linksys WRT54G router uses the same private key and certificate for every router, which allows remote attackers to sniff...
CVE-2005-2430——Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5 allow remote attackers to inject arbitrary web script ...
CVE-2005-2435——Cross-site scripting (XSS) vulnerability in browse.php in Website Baker Project allows remote attackers to inject arbitr...
CVE-2005-2419——B-FOCuS Router 312+ allows remote attackers to bypass authentication and gain unauthorized access via a direct request t...
CVE-2005-2417——Contrexx before 1.0.5 allows remote attackers to obtain sensitive information via a direct request to /config/version.xm...
CVE-2005-2416——Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary ...
CVE-2005-2415——Multiple SQL injection vulnerabilities in Contrexx before 1.0.5 allow remote attackers to execute arbitrary SQL commands...
CVE-2005-2414——Race condition in the xpcom library, as used by web browsers such as Firefox, Mozilla, Netscape, and Galeon, allows remo...
CVE-2005-2413——PHP remote file inclusion vulnerability in apa_phpinclude.inc.php in Atomic Photo Album (APA) allows remote attackers to...
CVE-2005-2412——PHP remote file inclusion vulnerability in block.php in PHP FirstPost allows remote attackers to execute arbitrary PHP c...
CVE-2005-2431——The (1) lost password and (2) account pending features in GForge 4.5 do not properly set a limit on the number of e-mail...
CVE-2005-2420——flsearch.pl in FtpLocate 2.02 allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP ...
CVE-2005-2421——Multiple SQL injection vulnerabilities in index.php and other pages in Beehive Forum allow remote attackers to execute a...
CVE-2005-2422——Cross-site scripting (XSS) vulnerability in index.php in Beehive Forum allows remote attackers to inject arbitrary web s...
CVE-2005-1853——gopher.c in the Gopher client 3.0.5 does not properly create temporary files, which allows local users to gain privilege...
CVE-2005-2446——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-2369. Reason: This candidate is a duplicate of...

Check if your code is affected by 2005 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now