2005 CVE Vulnerabilities

4,770 CVEs published in 2005.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2005-3765——Exponent CMS 0.96.3 and later versions performs a chmod on uploaded files to give them execute permissions, which allows...
CVE-2005-3760——Double free vulnerability in the BBOORB module in IBM WebSphere Application Server for z/OS 5.0 allows attackers to caus...
CVE-2005-3762——SQL injection vulnerability in the navigation module (navigationmodule) in Exponent CMS 0.96.3 and later versions allows...
CVE-2005-3763——Exponent CMS 0.96.3 and later versions includes the full installation path in the base parameter to thumb.php, which all...
CVE-2005-3764——The image gallery (imagegallery) component in Exponent CMS 0.96.3 and later versions does not properly check the MIME ty...
CVE-2005-3766——Exponent CMS 0.96.3 and later versions stores sensitive user pages under the web document root with insufficient access ...
CVE-2005-3767——Exponent CMS 0.96.3 and later versions does not properly restrict the types of uploaded files, which allows remote attac...
CVE-2005-3757——The Saxon XSLT parser in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to ...
CVE-2005-3756——Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to port scan arbitrary hosts...
CVE-2005-3754——Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows r...
CVE-2005-3755——Directory traversal vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote a...
CVE-2005-3758——Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows r...
CVE-2005-3759——Multiple cross-site scripting (XSS) vulnerabilities in Horde before 3.0.7 allow remote attackers to inject arbitrary web...
CVE-2005-3751——HTTP request smuggling vulnerability in Pound before 1.9.4 allows remote attackers to poison web caches, bypass web appl...
CVE-2005-3752——Unspecified vulnerability in ldapdiff before 1.1.1 has unknown impact and attack vectors, related to "ldapdiff.conf path...
CVE-2005-3753——Linux kernel before after 2.6.12 and before 2.6.13.1 might allow attackers to cause a denial of service (Oops) via certa...
CVE-2005-3750——Opera before 8.51 on Linux and Unix systems allows remote attackers to execute arbitrary code via shell metacharacters (...
CVE-2005-3741——Almond Classifieds does not properly verify the password, which allows attackers to bypass access restrictions.
CVE-2005-3738——globals.php in Mambo Site Server 4.0.14 and earlier, when register_globals is disabled, allows remote attackers to overw...
CVE-2005-3739——Unspecified vulnerability in subheader.php in PHP-Fusion 6.00.206 and earlier allows remote attackers to obtain the full...
CVE-2005-3740——Multiple SQL injection vulnerabilities in PHP-Fusion 6.00.206 and earlier allow remote attackers to execute arbitrary SQ...
CVE-2005-3742——Cross-site scripting (XSS) vulnerability in popup.php in Advanced Poll 2.0.3 and earlier allows remote attackers to inje...
CVE-2005-3743——SQL injection vulnerability in results.php in SimplePoll allows remote attackers to execute arbitrary SQL commands via t...
CVE-2005-3744——SQL injection vulnerability in index.php in phpComasy 0.7.5 and earlier allows remote attackers to execute arbitrary SQL...
CVE-2005-3745——Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to ...

Check if your code is affected by 2005 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now