2005 CVE Vulnerabilities

4,770 CVEs published in 2005.

CVE IDSeverityCVSSDescription
CVE-2005-1645Keyvan1 ImageGallery stores the image.mdb database under the web document root with insufficient access control, which a...
CVE-2005-1646The default installation of Fastream NETFile FTP/Web Server 7.4.6, which supports FXP, does not require that the IP addr...
CVE-2005-1647Gurgens (GASoft) Guest Book 2.1 stores the db/Genid.dat database file under the web document root with insufficient acce...
CVE-2005-1648Gurgens (GASoft) Ultimate Forum 1.0 stores the db/Genid.dat database file under the web document root with insufficient ...
CVE-2005-1631booby.php in Booby 1.0.0 and earlier allows remote attackers to view private bookmarks by guessing item IDs.
CVE-2005-1632Cheetah 0.9.15 and 0.9.16 searches the /tmp directory for modules before using the paths in the PYTHONPATH variable, whi...
CVE-2005-1633Multiple SQL injection vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to execute arbitrar...
CVE-2005-1630Unknown vulnerability in Attachment Mod before 2.3.13, related to a "serious issue with realnames," has unknown impact a...
CVE-2005-1634Multiple cross-site scripting (XSS) vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to inj...
CVE-2005-1635JGS-XA JGS-Portal 3.0.2 and earlier allows remote attackers to obtain the full server path via direct requests to (1) jg...
CVE-2005-1636mysql_install_db in MySQL 4.1.x before 4.1.12 and 5.x up to 5.0.4 creates the mysql_install_db.X file with a predictable...
CVE-2005-1637Multiple SQL injection vulnerabilities in NPDS 4.8 and 5.0 allow remote attackers to execute arbitrary SQL commands via ...
CVE-2005-1638The _writeAttrs function in SafeHTML before 1.3.2 does not properly handle quotes in attribute values, which could allow...
CVE-2005-1639SQL injection vulnerability in Sigmaweb.DLL in Sigma ISP Manager 6.6 allows remote attackers to execute arbitrary SQL co...
CVE-2005-1640mod_channel.bas in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not properly ...
CVE-2005-1641mod_channel in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not allow protect...
CVE-2005-1642SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attacker...
CVE-2005-1643The ZCom_BitStream::Deserialize function in Zoidcom 1.0 beta 4 and earlier allows remote attackers to cause a denial of ...
CVE-2005-1307The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory...
CVE-2005-1627Unknown vulnerability in Viewglob before 2.0.1, related to "a potential security issue with the Viewglob display and ssh...
CVE-2005-1589The pkt_ioctl function in the pktcdvd block device ioctl handler (pktcdvd.c) in Linux kernel 2.6.12-rc4 and earlier call...
CVE-2005-1628apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote attackers to execute arbitrary commands via ...
CVE-2005-1629SQL injection vulnerability in member.php for Photopost PHP Pro allows remote attackers to execute arbitrary SQL command...
CVE-2005-1264Raw character devices (raw.c) in the Linux kernel 2.6.x call the wrong function before passing an ioctl to the block dev...
CVE-2005-1626Multiple buffer overflows in handlers.c for Pico Server (pServ) before 3.3 may allow attackers to execute arbitrary code...

Check if your code is affected by 2005 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now