2005 CVE Vulnerabilities

4,770 CVEs published in 2005.

CVE IDSeverityCVSSDescription
CVE-2005-2214——apt-setup in Debian GNU/Linux installs the apt.conf file with insecure permissions, which allows local users to obtain s...
CVE-2005-2213——Buffer overflow in the mms_interp_header function in mms.c in MMS Ripper before 0.6.4 might allow remote attackers to ex...
CVE-2005-2209MEDIUM5.5Capturix ScanShare 1.06 build 50 stores sensitive information such as the password in cleartext in capturixss_cfg.ini, w...
CVE-2005-2212——Backup Manager 0.5.8a creates an archive repository with world readable and writable permissions, which allows attackers...
CVE-2005-2211——Backup Manager 0.5.8a creates temporary files insecurely, which allows local users to conduct unauthorized file operatio...
CVE-2005-2210——Stack-based buffer overflow in Internet Download Manager 4.05 allows remote attackers to execute arbitrary code via a lo...
CVE-2005-2208——PrivaShare 1.1b allows remote attackers to cause a denial of service (crash) via a malformed message.
CVE-2005-2182HIGH7.5Grandstream BudgeTone (BT) 100 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in ...
CVE-2005-2207——Cross-site scripting (XSS) vulnerability in store/login.asp in CartWIZ allows remote attackers to inject arbitrary web s...
CVE-2005-2206——Multiple SQL injection vulnerabilities in CartWIZ allow remote attackers to modify SQL statements via the (1) idProduct ...
CVE-2005-2181HIGH7.5Cisco 7940/7960 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY messag...
CVE-2005-2205——The ReadLog function in kaiseki.cgi in pngren allows remote attackers to execute arbitrary commands via shell metacharac...
CVE-2005-2204——Cross-site scripting (XSS) vulnerability in Computer Associates (CA) eTrust SiteMinder 5.5, when the "CSSChecking" param...
CVE-2005-1848——The dhcpcd DHCP client before 1.3.22 allows remote attackers to cause a denial of service (daemon crash) via unknown vec...
CVE-2005-2203——login.php in phpWishlist before 0.1.15 allows remote attackers to bypass authentication via a direct request to admin.ph...
CVE-2005-2202——Cross-site scripting (XSS) vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 35...
CVE-2005-2201——Unknown vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.0...
CVE-2005-2199——PHP remote file inclusion vulnerability in inc/functions.inc.php in PPA web photo gallery 0.5.6 allows remote attackers ...
CVE-2005-2198——PHP remote file inclusion vulnerability in lang.php in SPiD before 1.3.1 allows remote attackers to execute arbitrary co...
CVE-2005-1768——Race condition in the ia32 compatibility code for the execve system call in Linux kernel 2.4 before 2.4.31 and 2.6 befor...
CVE-2005-2197——SQL injection vulnerability in sql.cls.php in Id Board 1.1.3 allows remote attackers to modify SQL queries, as demonstra...
CVE-2005-2193——SQL injection vulnerability in the user profile edit module in profile.php for PunBB 1.2.5 and earlier allows remote att...
CVE-2005-2192——SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote ...
CVE-2005-2191——Multiple cross-site scripting (XSS) vulnerabilities in Comersus shopping cart allow remote attackers to inject arbitrary...
CVE-2005-2190——Multiple SQL injection vulnerabilities in Comersus shopping cart allow remote attackers to execute arbitrary SQL command...

Check if your code is affected by 2005 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now