2005 CVE Vulnerabilities

4,770 CVEs published in 2005.

CVE IDSeverityCVSSDescription
CVE-2005-1550easymsgb.pl in Easy Message Board allows remote attackers to execute arbitrary commands via shell metacharacters in the ...
CVE-2005-1551Sophos Anti-Virus 3.93 does not check downloaded files for viruses when they have only been written, which creates a rac...
CVE-2005-1575The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows allows remote attackers to hide the real file typ...
CVE-2005-1544Stack-based buffer overflow in libTIFF before 3.7.2 allows remote attackers to execute arbitrary code via a TIFF file wi...
CVE-2005-1577APG Technology ClassMaster does not properly restrict access to sensitive folders, which allows remote attackers to acce...
CVE-2005-1574Windows Media Player 9 and 10, in certain cases, allows content protected by Windows Media Digital Rights Management (WM...
CVE-2005-1587Cross-site scripting (XSS) vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to inject arbitrary w...
CVE-2005-1563Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 displays a different error message depending on whether a product exists ...
CVE-2005-1571Multiple directory traversal vulnerabilities in ShowOff! 1.5.4 allow remote attackers to read arbitrary files via ".." s...
CVE-2005-1570forum.asp in bttlxeForum 2.0 allows remote attackers to obtain full path information via a certain hex-encoded argument ...
CVE-2005-1569Cross-site scripting (XSS) vulnerability in DirectTopics 2.1 and 2.2 allows remote attackers to inject arbitrary web scr...
CVE-2005-1566Acrowave AAP-3100AR wireless router allows remote attackers to bypass authentication by pressing CTRL-C at the username ...
CVE-2005-1586Quick.Forum 2.1.6 stores potentially sensitive information such as usernames, banned IP addresses, censored words, and b...
CVE-2005-1545Integer overflow in the ELF parser in HT Editor before 0.8.0 allows remote attackers to execute arbitrary code via a cra...
CVE-2005-0758zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands ...
CVE-2005-1578EnCase Forensic Edition 4.18a does not support Device Configuration Overlays (DCO), which allows attackers to hide infor...
CVE-2005-1576The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows uses the Content-Type HTTP header to determine th...
CVE-2005-1579Apple QuickTime Player 7.0 on Mac OS X 10.4 allows remote attackers to obtain sensitive information via a .mov file with...
CVE-2005-0974Unknown vulnerability in the nfs_mount call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via cra...
CVE-2005-0971Stack-based buffer overflow in the semop system call in Mac OS X 10.3.9 and earlier allows local users to gain privilege...
CVE-2005-1568topic.php in DirectTopics 2.1 and 2.2 allows remote attackers to obtain sensitive information via an invalid topic param...
CVE-2005-1567SQL injection vulnerability in topic.php in DirectTopics 2.1 and 2.2 allows remote attackers to execute arbitrary SQL co...
CVE-2005-1531Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injec...
CVE-2005-1565Bugzilla 2.17.1 through 2.18, 2.19.1, and 2.19.2, when a user is prompted to log in while attempting to view a chart, di...
CVE-2005-1564post_bug.cgi in Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 allows remote authenticated users to "enter bugs into pro...

Check if your code is affected by 2005 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now