2005 CVE Vulnerabilities

4,770 CVEs published in 2005.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2005-2221——Multiple SQL injection vulnerabilities in Dragonfly Commerce allows remote attackers to modify SQL statements and possib...
CVE-2005-2220——Dragonfly Commerce allows remote attackers to change a product price by modifying the x_DragonflyCartProductPrice hidden...
CVE-2005-2219——Hosting Controller 6.1 Hotfix 2.1 allows remote authenticated users to perform unauthorized actions, such as modifying t...
CVE-2005-2217——Dansie Shopping Cart stores the vars.dat file under the web root with insufficient access control, which might allow rem...
CVE-2005-2216——PHP remote file inclusion vulnerability in gals.php in PhotoGal Photo Gallery 1.5 and earlier allows remote attackers to...
CVE-2005-2215——Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.x before 1.4.6 and 1.5 before 1.5beta3 allows remote at...
CVE-2005-0564——Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 through 2004, might al...
CVE-2005-1219——Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code v...
CVE-2005-1859——Unknown vulnerability in arshell in the Array Service (arrayd) for SGI ProPack 3 with SP 5 and 6, and SGI ProPack 4, all...
CVE-2005-2247——Multiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact and attack vectors.
CVE-2005-2184——eRoom 6.x does not properly restrict files that can be attached, which allows remote attackers to execute arbitrary comm...
CVE-2005-2183——class.xmail.php in PhpXmail 0.7 through 1.1 does not properly handle large passwords, which prevents an error message fr...
CVE-2005-2180——gen-index in GNATS 4.0, 4.1.0, and possibly earlier versions, when installed setuid, does not properly check files passe...
CVE-2005-2179——PHP remote file inclusion vulnerability in BlogModel.php in Jaws 0.5.2 and earlier allows remote attackers to execute ar...
CVE-2005-2178——probe.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the olddat parameter. NOTE:...
CVE-2005-2189——Lantronix SecureLinx console server running firmware 2.0 and 3.0 stores /etc/ssh under the web document root with insuff...
CVE-2005-2177——Net-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when net-snmp is using stream sockets such as TCP, allo...
CVE-2005-2190——Multiple SQL injection vulnerabilities in Comersus shopping cart allow remote attackers to execute arbitrary SQL command...
CVE-2005-2191——Multiple cross-site scripting (XSS) vulnerabilities in Comersus shopping cart allow remote attackers to inject arbitrary...
CVE-2005-2170——The LCF component (lcfd) in IBM Tivoli Management Framework Endpoint allows remote attackers to cause a denial of servic...
CVE-2005-2192——SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote ...
CVE-2005-2193——SQL injection vulnerability in the user profile edit module in profile.php for PunBB 1.2.5 and earlier allows remote att...
CVE-2005-2197——SQL injection vulnerability in sql.cls.php in Id Board 1.1.3 allows remote attackers to modify SQL queries, as demonstra...
CVE-2005-2198——PHP remote file inclusion vulnerability in lang.php in SPiD before 1.3.1 allows remote attackers to execute arbitrary co...
CVE-2005-2199——PHP remote file inclusion vulnerability in inc/functions.inc.php in PPA web photo gallery 0.5.6 allows remote attackers ...

Check if your code is affected by 2005 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now