Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-1650 1 Woppoware 1 Postmaster 2008-09-05 7.5 HIGH N/A
The web mail service in Woppoware PostMaster 4.2.2 (build 3.2.5) generates different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames.
CVE-2005-1629 1 Photopost 1 Photopost Php Pro 2008-09-05 7.5 HIGH N/A
SQL injection vulnerability in member.php for Photopost PHP Pro allows remote attackers to execute arbitrary SQL commands via the verifykey parameter.
CVE-2005-1637 1 Npds 1 Npds 2008-09-05 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in NPDS 4.8 and 5.0 allow remote attackers to execute arbitrary SQL commands via the thold parameter to (1) comments.php or (2) pollcomments.php.
CVE-2005-1451 1 S9y 1 Serendipity 2008-09-05 7.5 HIGH N/A
The media manager in Serendipity before 0.8 allows remote attackers to upload and execute arbitrary (1) .php or (2) .shtml files.
CVE-2005-1577 1 Apg Technology 1 Classmaster 2008-09-05 7.5 HIGH N/A
APG Technology ClassMaster does not properly restrict access to sensitive folders, which allows remote attackers to access folders via a network share.
CVE-2005-1452 1 S9y 1 Serendipity 2008-09-05 10.0 HIGH N/A
Serendipity before 0.8 allows Chief users to "hide plugins installed by other users."
CVE-2005-1592 1 Birdblog 1 Birdblog 2008-09-05 7.5 HIGH N/A
Multiple "javascript vulerabilities in BB code" in BirdBlog before 1.3.1 allow remote attackers to inject arbitrary Javascript.
CVE-2005-1638 1 Pixel-apes Group 1 Safehtml 2008-09-05 4.3 MEDIUM N/A
The _writeAttrs function in SafeHTML before 1.3.2 does not properly handle quotes in attribute values, which could allow remote attackers to exploit cross-site scripting (XSS) vulnerabilities in applications that rely on SafeHTML for protection.
CVE-2005-1522 1 Gnu 1 Mailutils 2008-09-05 5.0 MEDIUM N/A
The imap4d server for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows authenticated remote users to cause a denial of service (CPU consumption) via a large range value in the FETCH command.
CVE-2005-1573 1 Darrel Oneil 1 Asp Virtual News Manager 2008-09-05 7.5 HIGH N/A
SQL injection vulnerability in admin_login.asp for ASP Virtual News Manager allows remote attackers to execute arbitrary SQL commands via the password parameter.
CVE-2005-1572 1 Wenig And Spitzer-williams 1 Showoff Digital Media Software 2008-09-05 5.0 MEDIUM N/A
ShowOff! 1.5.4 allows remote attackers to cause a denial of service (server crash) via a malformed request to port 8083.
CVE-2005-1576 1 Mozilla 1 Firefox 2008-09-05 2.6 LOW N/A
The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows uses the Content-Type HTTP header to determine the file type, but saves the original file extension when "Save to Disk" is selected, which allows remote attackers to hide the real file types of downloaded files.
CVE-2005-1575 1 Mozilla 1 Firefox 2008-09-05 5.0 MEDIUM N/A
The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows allows remote attackers to hide the real file types of downloaded files via the Content-Type HTTP header and a filename containing whitespace, dots, or ASCII byte 160.
CVE-2005-1590 1 Altiris 2 Client Service, Deployment Solution 2008-09-05 4.6 MEDIUM N/A
The Altiris Client Service for Windows (ACLIENT.EXE) 6.0.88 allows local users to disable password protection and access the administrative interface by finding and showing the "Altiris Client Service" hidden window, disabling the password protection, disabling the "Hide client tray icon box" option, then opening the AClient tray icon and using the View Log File option, a different vulnerability than CVE-2004-2070.
CVE-2005-1588 1 Open Solution 1 Quick.cart 2008-09-05 7.5 HIGH N/A
** DISPUTED ** SQL injection vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to execute arbitrary SQL commands via the iCategory parameter. NOTE: the vendor has privately disputed this issue, saying that Quick.cart does not even use SQL and therefore can not be vulnerable to SQL injection.
CVE-2005-1523 1 Gnu 1 Mailutils 2008-09-05 7.5 HIGH N/A
Format string vulnerability in imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via format string specifiers in the command tag for IMAP commands.
CVE-2005-1570 1 Battleaxe Software 1 Bttlxeforum 2008-09-05 5.0 MEDIUM N/A
forum.asp in bttlxeForum 2.0 allows remote attackers to obtain full path information via a certain hex-encoded argument to the page parameter, possibly due to a SQL injection vulnerability.
CVE-2005-1641 1 The Ignition Project 1 Ignitionserver 2008-09-05 2.1 LOW N/A
mod_channel in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not allow protected operators to access channels that have been locked out by a key, which allows IRC users to cause a denial of service.
CVE-2005-1400 1 Freebsd 1 Freebsd 2008-09-05 4.6 MEDIUM N/A
The i386_get_ldt system call in FreeBSD 4.7 to 4.11 and 5.x to 5.4 allows local users to access sensitive kernel memory via arguments with negative or very large values.
CVE-2005-1401 1 Mtp-target 1 Mtp-target 2008-09-05 7.5 HIGH N/A
Format string vulnerability in the client for Mtp-Target 1.2.2 and earlier allows remote attackers to execute arbitrary code via game messages or other text.
CVE-2005-1640 1 The Ignition Project 1 Ignitionserver 2008-09-05 7.5 HIGH N/A
mod_channel.bas in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not properly verify whether a host has the owner privileges required to delete IRC channel access entries, which allows remote attackers to bypass intended restrictions.
CVE-2005-1402 1 Mtp-target 1 Mtp-target 2008-09-05 5.0 MEDIUM N/A
Integer signedness error in certain older versions of the NeL library, as used in Mtp-Target 1.2.2 and earlier, and possibly other products, allows remote attackers to cause a denial of service (memory consumption or server crash) via a negative value in a STLport call, which is not caught by a signed comparison.
CVE-2005-1403 1 Just Williams 1 Amazon Webstore 2008-09-05 6.8 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in JustWilliam's Amazon Webstore 04050100 allow remote attackers to inject arbitrary web script or HTML via the (1) image parameter to closeup.php, the (2) currentIsExpanded or (3) searchFor parameters to index.php, (4) the currentNumber parameter to software_CAD_Technical_60002_uk.htm, or (5) a cookie.
CVE-2005-1404 1 Myphp Forum 1 Myphp Forum 2008-09-05 5.0 MEDIUM N/A
MyPHP Forum 1.0 allows remote attackers to spoof the username by modifying the (1) nbuser parameter to post.php or (2) sender parameter to privmsg.php.
CVE-2005-1653 1 Woppoware 1 Postmaster 2008-09-05 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to inject arbitrary web script or HTML via the email parameter.
CVE-2005-1337 1 Apple 2 Mac Os X, Mac Os X Server 2008-09-05 7.5 HIGH N/A
Apple Help Viewer 2.0.7 and 3.0.0 in Mac OS X 10.3.9 allows remote attackers to read and execute arbitrary scrpts with less restrictive privileges via a help:// URI.
CVE-2005-1067 1 Access User Class 1 Access User Class 2008-09-05 7.5 HIGH N/A
Vulnerability in Access_user Class before 1.75 allows local users to gain access as other users via the password "new".
CVE-2005-1072 1 Punbb 1 Punbb 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in PunBB before 1.2.5 allows remote attackers to inject arbitrary web script or HTML.
CVE-2005-1083 1 Aewebworks 1 Aedating 2008-09-05 5.0 MEDIUM N/A
index.php in aeDating 3.2 allows remote attackers to include arbitrary files via the skin parameter.
CVE-2005-1084 1 Aewebworks 1 Aedating 2008-09-05 7.5 HIGH N/A
SQL injection vulnerability in sdating.php in aeDating 3.2 allows remote attackers to execute arbitrary SQL commands files via the event parameter.
CVE-2005-1085 1 Aewebworks 1 Aedating 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the control panel in aeDating 3.2 allows remote attackers to inject arbitrary web script or HTML.
CVE-2005-1089 1 Dc\+\+ 1 Dc\+\+ 2008-09-05 5.0 MEDIUM N/A
Unknown vulnerability in DC++ before 0.674 allows attackers to append data to arbitrary files.
CVE-2005-1091 1 Maxthon 1 Maxthon 2008-09-05 7.5 HIGH N/A
Maxthon 1.2.0 and 1.2.1 allows remote attackers to bypass the security ID and use restricted plugin API functions via script that includes the max.src file into the source page.
CVE-2005-1092 1 Light Speed Technology 1 Deluxeftp 2008-09-05 7.2 HIGH N/A
Lightspeed DeluxeFTP 6.01 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges.
CVE-2005-1125 1 Avaya 1 Libsafe 2008-09-05 5.1 MEDIUM N/A
Race condition in libsafe 2.0.16 and earlier, when running in multi-threaded applications, allows attackers to bypass libsafe protection and exploit other vulnerabilities before the _libsafe_die function call is completed.
CVE-2005-1128 1 Virtual Hosting Control System 1 Virtual Hosting Control System 2008-09-05 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in VHCS 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via certain inputs from HTTP POST queries.
CVE-2005-1131 1 Symantec Veritas 1 I3 Focalpoint Server 2008-09-05 10.0 HIGH N/A
Unknown vulnerability in Veritas i3 Focalpoint Server 7.1 and earlier has unknown attack vectors and unknown but "critical" impact.
CVE-2005-1066 1 University Of Washington 1 Pine 2008-09-05 1.2 LOW N/A
Race condition in rpdump in Pine 4.62 and earlier allows local users to overwrite arbitrary files via a symlink attack.
CVE-2005-1138 1 Kerio 1 Kerio Mailserver 2008-09-05 5.0 MEDIUM N/A
Unknown vulnerability in WebMail in Kerio MailServer before 6.0.9 allows remote attackers to cause a denial of service (CPU consumption) via certain e-mail messages.
CVE-2005-1140 1 Mywebland 1 Mybloggie 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in myBloggie 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the comments.
CVE-2005-1065 1 Novell 1 Linux Desktop 2008-09-05 2.1 LOW N/A
tetex in Novell Linux Desktop 9 allows local users to determine the existence of arbitrary files via a symlink attack in the /var/cache/fonts directory.
CVE-2005-1231 1 Jaws 1 Jaws 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the NewTerm function in GlossaryModel.php in JAWS 0.4 allows remote attackers to inject arbitrary web script or HTML via the (1) term or (2) description.
CVE-2005-1311 1 Yappa-ng 1 Yappa-ng 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Yappa-NG before 2.3.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
CVE-2005-1312 1 Yappa-ng 1 Yappa-ng 2008-09-05 7.5 HIGH N/A
PHP remote file inclusion vulnerability in Yappa-NG before 2.3.2 allows remote attackers to execute arbitrary PHP code via unknown vectors.
CVE-2005-1313 1 Horde 1 Passwd 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Horde Passwd module before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
CVE-2005-1314 1 Horde 1 Kronolith 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Horde Kronolith module before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
CVE-2005-1319 1 Horde 1 Imp 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Horde IMP Webmail client before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
CVE-2005-1320 1 Horde 1 Mnemo 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Horde Mnemo Note Manager before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
CVE-2005-1321 1 Horde 1 Vaction 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Horde Vacation module before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
CVE-2005-1322 1 Horde 1 Nag 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Horde Nag Task List Manager before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.