2005 CVE Vulnerabilities

4,770 CVEs published in 2005.

CVE IDSeverityCVSSDescription
CVE-2005-2946HIGH7.5The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographica...
CVE-2005-2945——arc 5.21j and earlier create temporary files with world-readable permissions, which allows local users to read sensitive...
CVE-2005-2877——The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary co...
CVE-2005-2944——The perform_file_save function in GNOME Workstation Command Center (gwcc) 0.9.6 and earlier allows local users to create...
CVE-2005-2935——Unquoted Windows search path vulnerability in Microsoft AntiSpyware might allow local users to execute code via a malici...
CVE-2005-2918——The open_cmd_tube function in mount.c for gtkdiskfree 1.9.3 and earlier allows local users to overwrite arbitrary files ...
CVE-2005-2658——Buffer overflow in utility.cpp in Turquoise SuperStat (turqstat) 2.2.4 and earlier might allow remote NNTP servers to ex...
CVE-2005-2495——Multiple integer overflows in XFree86 before 4.3.0 allow user-assisted attackers to execute arbitrary code via a crafted...
CVE-2005-2799——Buffer overflow in apply.cgi in Linksys WRT54G 3.01.03, 3.03.6, and possibly other versions before 4.20.7, allows remote...
CVE-2005-2912——Linksys WRT54G router allows remote attackers to cause a denial of service (CPU consumption and server hang) via an HTTP...
CVE-2005-2914——ezconfig.asp in Linksys WRT54G router 3.01.03, 3.03.6, non-default configurations of 2.04.4, and possibly other versions...
CVE-2005-2915——ezconfig.asp in Linksys WRT54G router 3.01.03, 3.03.6, non-default configurations of 2.04.4, and possibly other versions...
CVE-2005-2916——Linksys WRT54G 3.01.03, 3.03.6, 4.00.7, and possibly other versions before 4.20.7, does not verify user authentication u...
CVE-2005-2913——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-2799. Reason: This candidate is a duplicate of...
CVE-2005-2904——Zebedee 2.4.1, when "allowed redirection port" is not set, allows remote attackers to cause a denial of service (applica...
CVE-2005-2879——Advansysperu Software USB Lock Auto-Protect (AP) 1.5 uses a weak encryption scheme to encrypt passwords, which allows lo...
CVE-2005-2888——Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) Preview Release 2 allow remote attackers to execute arb...
CVE-2005-2880——Multiple SQL injection vulnerabilities in phpCommunityCalendar 4.0.3, and possibly earlier versions, allow remote attack...
CVE-2005-2881——phpCommunityCalendar 4.0.3 allows remote attackers to bypass authentication and gain unauthorized access via a direct re...
CVE-2005-2882——Multiple cross-site scripting (XSS) vulnerabilities in phpCommunityCalendar 4.0.3, and possibly earlier versions, allow ...
CVE-2005-2884——Cross-site scripting (XSS) vulnerability in events.php in Land Down Under (LDU) 801 and earlier allows remote attackers ...
CVE-2005-2885——The Downloads page in MAXdev MD-Pro 1.0.73, and possibly earlier versions, uses an incomplete blacklist to check for dan...
CVE-2005-2886——Multiple cross-site scripting (XSS) vulnerabilities in MAXdev MD-Pro 1.0.73, and possibly earlier versions, allow remote...
CVE-2005-2887——MAXdev MD-Pro 1.0.73, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direc...
CVE-2005-2889——Check Point NGX R60 does not properly verify packets against the predefined service group "CIFS" rule, which allows remo...

Check if your code is affected by 2005 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now