2005 CVE Vulnerabilities

4,770 CVEs published in 2005.

CVE IDSeverityCVSSDescription
CVE-2005-3765——Exponent CMS 0.96.3 and later versions performs a chmod on uploaded files to give them execute permissions, which allows...
CVE-2005-3766——Exponent CMS 0.96.3 and later versions stores sensitive user pages under the web document root with insufficient access ...
CVE-2005-3767——Exponent CMS 0.96.3 and later versions does not properly restrict the types of uploaded files, which allows remote attac...
CVE-2005-3757——The Saxon XSLT parser in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to ...
CVE-2005-3758——Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows r...
CVE-2005-3754——Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows r...
CVE-2005-3755——Directory traversal vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote a...
CVE-2005-3756——Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to port scan arbitrary hosts...
CVE-2005-3759——Multiple cross-site scripting (XSS) vulnerabilities in Horde before 3.0.7 allow remote attackers to inject arbitrary web...
CVE-2005-3753——Linux kernel before after 2.6.12 and before 2.6.13.1 might allow attackers to cause a denial of service (Oops) via certa...
CVE-2005-3751——HTTP request smuggling vulnerability in Pound before 1.9.4 allows remote attackers to poison web caches, bypass web appl...
CVE-2005-3752——Unspecified vulnerability in ldapdiff before 1.1.1 has unknown impact and attack vectors, related to "ldapdiff.conf path...
CVE-2005-3750——Opera before 8.51 on Linux and Unix systems allows remote attackers to execute arbitrary code via shell metacharacters (...
CVE-2005-3742——Cross-site scripting (XSS) vulnerability in popup.php in Advanced Poll 2.0.3 and earlier allows remote attackers to inje...
CVE-2005-3738——globals.php in Mambo Site Server 4.0.14 and earlier, when register_globals is disabled, allows remote attackers to overw...
CVE-2005-3739——Unspecified vulnerability in subheader.php in PHP-Fusion 6.00.206 and earlier allows remote attackers to obtain the full...
CVE-2005-3740——Multiple SQL injection vulnerabilities in PHP-Fusion 6.00.206 and earlier allow remote attackers to execute arbitrary SQ...
CVE-2005-3741——Almond Classifieds does not properly verify the password, which allows attackers to bypass access restrictions.
CVE-2005-3743——SQL injection vulnerability in results.php in SimplePoll allows remote attackers to execute arbitrary SQL commands via t...
CVE-2005-3744——SQL injection vulnerability in index.php in phpComasy 0.7.5 and earlier allows remote attackers to execute arbitrary SQL...
CVE-2005-3745——Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to ...
CVE-2005-3746——SQL injection vulnerability in thread.php in APBoard allows remote attackers to execute arbitrary SQL commands via the s...
CVE-2005-3747——Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly inv...
CVE-2005-3748——SQL injection vulnerability in the Search module in Tru-Zone Nuke ET 3.2, and possibly earlier versions, allows remote a...
CVE-2005-3749——Unspecified "absolute path vulnerabilities" in the diagela command (diagela.sh) in IBM AIX 5.2 and 5.3 have unknown impa...

Check if your code is affected by 2005 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now