2005 CVE Vulnerabilities

4,770 CVEs published in 2005.

CVE IDSeverityCVSSDescription
CVE-2005-2170The LCF component (lcfd) in IBM Tivoli Management Framework Endpoint allows remote attackers to cause a denial of servic...
CVE-2005-2207Cross-site scripting (XSS) vulnerability in store/login.asp in CartWIZ allows remote attackers to inject arbitrary web s...
CVE-2005-2208PrivaShare 1.1b allows remote attackers to cause a denial of service (crash) via a malformed message.
CVE-2005-2150Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing ...
CVE-2005-2182HIGH7.5Grandstream BudgeTone (BT) 100 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in ...
CVE-2005-2210Stack-based buffer overflow in Internet Download Manager 4.05 allows remote attackers to execute arbitrary code via a lo...
CVE-2005-2211Backup Manager 0.5.8a creates temporary files insecurely, which allows local users to conduct unauthorized file operatio...
CVE-2005-2212Backup Manager 0.5.8a creates an archive repository with world readable and writable permissions, which allows attackers...
CVE-2005-2213Buffer overflow in the mms_interp_header function in mms.c in MMS Ripper before 0.6.4 might allow remote attackers to ex...
CVE-2005-2209MEDIUM5.5Capturix ScanShare 1.06 build 50 stores sensitive information such as the password in cleartext in capturixss_cfg.ini, w...
CVE-2005-2214apt-setup in Debian GNU/Linux installs the apt.conf file with insecure permissions, which allows local users to obtain s...
CVE-2005-2205The ReadLog function in kaiseki.cgi in pngren allows remote attackers to execute arbitrary commands via shell metacharac...
CVE-2005-2175The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save ...
CVE-2005-2176Novell NetMail automatically processes HTML in an attachment without prompting the user to save or open it, which makes ...
CVE-2005-2173The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the f...
CVE-2005-2174Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked...
CVE-2005-1912Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-1841. Reason: This candidate is a duplicate of...
CVE-2005-1841The control for Adobe Reader 5.0.9 and 5.0.10 on Linux, Solaris, HP-UX, and AIX creates temporary files with the permiss...
CVE-2005-2160HIGH7.5IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive informa...
CVE-2005-1916MEDIUM5.5linki.py in ekg 2005-06-05 and earlier allows local users to overwrite or create arbitrary files via a symlink attack on...
CVE-2005-2169Directory traversal vulnerability in source.php in Quick & Dirty PHPSource Printer 1.1 and earlier allows remote attacke...
CVE-2005-2168delete.php in Plague News System 0.6 and earlier allows remote unauthenticated attackers to delete news, comments, and s...
CVE-2005-2167Cross-site scripting (XSS) vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to i...
CVE-2005-2166SQL injection vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to execute arbitr...
CVE-2005-2165read.cgi in GlobalNoteScript allows remote attackers to execute arbitrary commands via shell metacharacters in the file ...

Check if your code is affected by 2005 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now