2005 CVE Vulnerabilities

4,770 CVEs published in 2005.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2005-2391Unknown vulnerability in 3Com OfficeConnect Wireless 11g Access Point before 1.03.12 allows remote attackers to obtain s...
CVE-2005-2393Cross-site scripting (XSS) vulnerability in CuteNews 1.3.6 allows remote attackers to inject arbitrary web script or HTM...
CVE-2005-2394show_news.php in CuteNews 1.3.6 allows remote attackers to obtain the full path of the server via an invalid archive par...
CVE-2005-2395Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as requ...
CVE-2005-2396Cross-site scripting (XSS) vulnerability in MediaWiki 1.4.6 and earlier allows remote attackers to inject arbitrary web ...
CVE-2005-2397Cross-site scripting (XSS) vulnerability in guestbook.php in phpBook 1.46 allows remote attackers to inject arbitrary we...
CVE-2005-2398Multiple SQL injection vulnerabilities in PHP Surveyor 0.98 allows remote attackers to execute arbitrary SQL commands vi...
CVE-2005-2399PHP Surveyor 0.98 allows remote attackers to trigger SQL errors via missing parameters to (1) browse.php, (2) export.php...
CVE-2005-2400The inc.login.php scripts in PHPFinance 0.3 allows remote attackers to bypass the login and gain privileges.
CVE-2005-2401PHP-Fusion allows remote attackers to inject arbitrary Cascading Style Sheets (CSS) via the BBCode color tag.
CVE-2005-2402Cross-site scripting (XSS) vulnerability in search.php in PHPSiteSearch 1.7.7d allows remote attackers to inject arbitra...
CVE-2005-2403The login protocol in RealChat 3.5.1b does not use authentication, which allows remote attackers to log on as other user...
CVE-2005-2404SQL injection vulnerability in sendcard.php in Sendcard 3.2.3 allows remote attackers to execute arbitrary SQL commands ...
CVE-2005-1852Multiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, GNU Gadu, CenterICQ, ...
CVE-2005-2218The device file system (devfs) in FreeBSD 5.x does not properly check parameters of the node type when creating a device...
CVE-2005-2370Multiple "memory alignment errors" in libgadu, as used in ekg before 1.6rc2, Gaim before 1.5.0, and other packages, allo...
CVE-2005-1849inftrees.h in zlib 1.2.2 allows remote attackers to cause a denial of service (application crash) via an invalid file th...
CVE-2005-2376Buffer overflow in Race Driver 1.20 and earlier allows remote attackers to cause a denial of service (application crash)...
CVE-2005-2377nss_ldap 181 to versions before 213, as used in Mandrake Corporate Server and Mandrake 10.0, and other operating systems...
CVE-2005-2378Directory traversal vulnerability in Oracle Reports allows remote attackers to read arbitrary files via an absolute or r...
CVE-2005-2383SQL injection vulnerability in auth.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via t...
CVE-2005-2379Multiple cross-site scripting (XSS) vulnerabilities in Oracle Reports 9.0.2 allow remote attackers to inject arbitrary w...
CVE-2005-2380Multiple cross-site scripting vulnerabilities in PHP Surveyor 0.98 allow remote attackers to inject arbitrary web script...
CVE-2005-2381PHP Surveyor 0.98 allows remote attackers to obtain sensitive information via a direct request to (1) question.php, (2) ...
CVE-2005-2382Oray PeanutHull 3.0.1.0 and earlier does not properly drop SYSTEM privileges when launched from the system tray, which a...

Check if your code is affected by 2005 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now