2005 CVE Vulnerabilities

4,770 CVEs published in 2005.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2005-1992——The XMLRPC server in utils.rb for the ruby library (libruby) 1.8 sets an invalid default value that prevents "security p...
CVE-2005-2013——paFAQ 1.0 Beta 4 allows remote attackers to obtain sensitive information via a direct request to admin/backup.php, which...
CVE-2005-2012——Multiple SQL injection vulnerabilities in login in paFAQ 1.0 Beta 4 allow remote attackers to execute arbitrary SQL comm...
CVE-2005-2038——Fortibus CMS 4.0.0 allows remote attackers to modify information of other users, including Admin, via the "My info" page...
CVE-2005-2025——Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggre...
CVE-2005-1993——Race condition in sudo 1.3.1 up to 1.6.8p8, when the ALL pseudo-command is used after a user entry in the sudoers file, ...
CVE-2005-2033——Directory traversal vulnerability in folderview.asp for Blue-Collar Productions i-Gallery 3.3 allows remote attackers to...
CVE-2005-2034——Cross-site scripting (XSS) vulnerability in folderview.asp for BlueCollar iGallery 3.3 allows remote attackers to inject...
CVE-2005-2021——Cross-site scripting (XSS) vulnerability in cPanel 9.1 and earlier allows remote attackers to inject arbitrary web scrip...
CVE-2005-2014——The "upload a language pack" feature in paFAQ 1.0 Beta 4 allows remote authenticated administrators to execute arbitrary...
CVE-2005-2039——Unknown vulnerability in "various plugins" for NanoBlogger 3.2.1 and earlier allows remote attackers to execute arbitrar...
CVE-2005-2007——Directory traversal vulnerability in Edgewall Trac 0.8.3 and earlier allows remote attackers to read or write arbitrary ...
CVE-2005-0773——Stack-based buffer overflow in VERITAS Backup Exec Remote Agent 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.3...
CVE-2005-2006——JBOSS 3.2.2 through 3.2.7 and 4.0.2 allows remote attackers to obtain sensitive information via a GET request (1) with a...
CVE-2005-2004——Multiple cross-site scripting vulnerabilities in Ultimate PHP Board (UPB) 1.9.6 GOLD and earlier allow remote attackers ...
CVE-2005-2043——Directory traversal vulnerability in XAMPP before 1.4.14 allows remote attackers to inject arbitrary HTML and PHP code v...
CVE-2005-2029——amaroK Web Frontend 1.3 stores the globals.inc file under the web root without a .php extension and insufficient access ...
CVE-2005-2024——Vipul Razor Agents (razor-agents) before 2.70 allows remote attackers to cause a denial of service via (1) certain "unus...
CVE-2005-2023——The send_pinentry_environment function in asshelp.c in gpg2 on SUSE Linux 9.3 does not properly handle certain options, ...
CVE-2005-2022——Unknown vulnerability in Webmail in iPlanet Messaging Server 5.2 Patch 1 and Sun ONE Messaging Server 6.2 allows remote ...
CVE-2005-2008——Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a ya...
CVE-2005-2026——Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 has a hard-coded account and password for debugging, whic...
CVE-2005-1973——Java Web Start in Java 2 Platform Standard Edition (J2SE) 5.0 and 5.0 Update 1 allows applications to assign permissions...
CVE-2005-1971——Directory traversal vulnerability in InteractivePHP FusionBB .11 Beta and earlier allows remote attackers to include arb...
CVE-2005-1970——Symantec pcAnywhere 10.5x and 11.x before 11.5, with "Launch with Windows" enabled, allows local users with physical acc...

Check if your code is affected by 2005 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now