2005 CVE Vulnerabilities

4,770 CVEs published in 2005.

CVE IDSeverityCVSSDescription
CVE-2005-2189——Lantronix SecureLinx console server running firmware 2.0 and 3.0 stores /etc/ssh under the web document root with insuff...
CVE-2005-2188——McAfee IntruShield Security Management System obtains the user ID from the URL, which allows remote attackers to guess t...
CVE-2005-2187——McAfee IntruShield Security Management System allows remote authenticated users to access the "Generate Reports" feature...
CVE-2005-2186——Multiple cross-site scripting (XSS) vulnerabilities in McAfee IntruShield Security Management System allow remote authen...
CVE-2005-2185——eRoom does not set an expiration for Cookies, which allows remote attackers to capture cookies and conduct replay attack...
CVE-2005-2184——eRoom 6.x does not properly restrict files that can be attached, which allows remote attackers to execute arbitrary comm...
CVE-2005-2183——class.xmail.php in PhpXmail 0.7 through 1.1 does not properly handle large passwords, which prevents an error message fr...
CVE-2005-2180——gen-index in GNATS 4.0, 4.1.0, and possibly earlier versions, when installed setuid, does not properly check files passe...
CVE-2005-2179——PHP remote file inclusion vulnerability in BlogModel.php in Jaws 0.5.2 and earlier allows remote attackers to execute ar...
CVE-2005-2178——probe.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the olddat parameter. NOTE:...
CVE-2005-2177——Net-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when net-snmp is using stream sockets such as TCP, allo...
CVE-2005-2170——The LCF component (lcfd) in IBM Tivoli Management Framework Endpoint allows remote attackers to cause a denial of servic...
CVE-2005-2175——The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save ...
CVE-2005-2176——Novell NetMail automatically processes HTML in an attachment without prompting the user to save or open it, which makes ...
CVE-2005-2174——Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked...
CVE-2005-2173——The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the f...
CVE-2005-1841——The control for Adobe Reader 5.0.9 and 5.0.10 on Linux, Solaris, HP-UX, and AIX creates temporary files with the permiss...
CVE-2005-1912——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-1841. Reason: This candidate is a duplicate of...
CVE-2005-2161——Cross-site scripting (XSS) vulnerability in phpBB 2.0.16 allows remote attackers to inject arbitrary web script or HTML ...
CVE-2005-2167——Cross-site scripting (XSS) vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to i...
CVE-2005-2160HIGH7.5IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive informa...
CVE-2005-2168——delete.php in Plague News System 0.6 and earlier allows remote unauthenticated attackers to delete news, comments, and s...
CVE-2005-1916MEDIUM5.5linki.py in ekg 2005-06-05 and earlier allows local users to overwrite or create arbitrary files via a symlink attack on...
CVE-2005-2096——zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream...
CVE-2005-2157——PHP remote file inclusion vulnerability in survey.inc.php for nabopoll 1.2 allows remote attackers to execute arbitrary ...

Check if your code is affected by 2005 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now