2005 CVE Vulnerabilities

4,770 CVEs published in 2005.

CVE IDSeverityCVSSDescription
CVE-2005-2293MEDIUM5.5Oracle Formsbuilder 9.0.4 stores database usernames and passwords in a temporary file, which is not deleted after it is ...
CVE-2005-2283——WebEOC before 6.0.2 does not properly restrict the size of an uploaded file, which allows remote authenticated users to ...
CVE-2005-2294——Oracle Forms 4.5, 6.0, 6i, and 9i on Unix, when a large number of records are retrieved by an Oracle form, stores a copy...
CVE-2005-2284——Multiple SQL injection vulnerabilities in WebEOC before 6.0.2 allow remote attackers to modify SQL statements via unknow...
CVE-2005-2295——NetPanzer 0.8 and earlier allows remote attackers to cause a denial of service (infinite loop) via a packet with a zero ...
CVE-2005-2288——Cross-site scripting (XSS) vulnerability in PHPCounter 7.2 allows remote attackers to inject arbitrary web script or HTM...
CVE-2005-2292——Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 stores cleartext passwords in (1) IDEConnections.xml, (2) XSQLConfig.xml and ...
CVE-2005-2291——Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 passes the cleartext password as a parameter when starting sqlplus, which all...
CVE-2005-2287——SoftiaCom wMailServer 1.0 and 2.0 allows remote attackers to cause a denial of service (application crash) via a large T...
CVE-2005-2277——Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via sh...
CVE-2005-2262——Firefox 1.0.3 and 1.0.4, and Netscape 8.0.2, allows remote attackers to execute arbitrary code by tricking the user into...
CVE-2005-2261——Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts ...
CVE-2005-2272——Safari version 2.0 (412) does not clearly associate a Javascript dialog box with the web page that generated it, which a...
CVE-2005-2273——Opera 7.x and 8 before 8.01 does not clearly associate a Javascript dialog box with the web page that generated it, whic...
CVE-2005-2260——The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does not properly d...
CVE-2005-2259——The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Ma...
CVE-2005-2258——PHP remote file inclusion vulnerability in photolist.inc.php in Squito Gallery 1.33 allows remote attackers to execute a...
CVE-2005-2257——The saveProfile function in PhpSlash 0.8.0 allows remote attackers to modify arbitrary profiles and gain privileges by m...
CVE-2005-2256——Encoded directory traversal vulnerability in phpPgAdmin 3.1 to 3.5.3 allows remote attackers to access arbitrary files v...
CVE-2005-2255——Directory traversal vulnerability in PhpAuction 2.5 allows remote attackers to read arbitrary files, include local PHP f...
CVE-2005-2254——Multiple cross-site scripting (XSS) vulnerabilities in PhpAuction 2.5 allow remote attackers to inject arbitrary web scr...
CVE-2005-2253——SQL injection vulnerability in PhpAuction 2.5 allow remote attackers to modify SQL queries via the category parameter to...
CVE-2005-2252——PhpAuction 2.5 allows remote attackers to bypass authentication and gain privileges as another user by setting the PHPAU...
CVE-2005-2251——PHP remote file inclusion vulnerability in secure.php in PHPSecurePages (phpSP) 0.28beta and earlier allows remote attac...
CVE-2005-2250——Buffer overflow in Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitr...

Check if your code is affected by 2005 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now