LiveActive security incident?Get immediate response
CVE archive

February 2005

Browse CVE records published in February 2005, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 461 matching CVEs · Page 6 of 10.

Unknown · CVSS Not scored

CVE-2005-0332: Directory traversal vulnerability in DeskNow Mail and Collaboration Server 2.5.12 allows remote attackers t...

Directory traversal vulnerability in DeskNow Mail and Collaboration Server 2.5.12 allows remote attackers to (1) upload and possibly execute files outside the directory via the AttachmentsKey parameter to attachment.do, as demonstrated using JSP pages, or (2) delete arbitrary files via the select_file parameter to file.do.

Published Feb 10, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-0174: Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via head...

Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.

Published Feb 6, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-0328: Zyxel P310, P314, P324 and Netgear RT311, RT314 running the latest firmware, allows remote attackers on the...

Zyxel P310, P314, P324 and Netgear RT311, RT314 running the latest firmware, allows remote attackers on the WAN to obtain the IP address of the LAN side interface by pinging a valid LAN IP address, which generates an ARP reply from the WAN address side that maps the LAN IP address to the WAN's MAC address.

Published Feb 10, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-0320: Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow...

Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to login.html, (2) accountid parameter to accountsettings_add.html, or the (3) note, (4) title, and (5) location fields to calendar.html.

Published Feb 10, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-0319: Direct remote injection vulnerability in modalfram.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to l...

Direct remote injection vulnerability in modalfram.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to load external webpages that appear to come from the WebAdmin server, which allows remote attackers to inject arbitrary HTML or web script to facilitate cross-site scripting (XSS) and phishing attacks.

Published Feb 10, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-0313: Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers...

Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload arbitrary files via certain parameters to upload.php or (2) read arbitrary files via certain parameters to download.php, and remote authenticated users to read, create, or delete arbitrary directories and files via the IMAP commands (3) CREATE, (4) EXAMINE, (5) SELECT, or (6) DELETE.

Published Feb 10, 2005 · Updated Aug 7, 2024