LiveActive security incident?Get immediate response
CVE archive

March 2005

Browse CVE records published in March 2005, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 42 of 392 matching CVEs · Page 8 of 8.

Unknown · CVSS Not scored

CVE-2005-0606: Cross-site scripting (XSS) vulnerability in settings.inc.php for CubeCart 2.0.0 through 2.0.5, as used in m...

Cross-site scripting (XSS) vulnerability in settings.inc.php for CubeCart 2.0.0 through 2.0.5, as used in multiple PHP files, allows remote attackers to inject arbitrary HTML or web script via the (1) cat_id, (2) PHPSESSID, (3) view_doc, (4) product, (5) session, (6) catname, (7) search, or (8) page parameters.

Published Mar 1, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-0581: Multiple buffer overflows in Computer Associates (CA) License Client and Server 0.1.0.15 allow remote attac...

Multiple buffer overflows in Computer Associates (CA) License Client and Server 0.1.0.15 allow remote attackers to execute arbitrary code via (1) certain long fields in the Checksum item in a GCR request, (2) a long IP address, hostname, or netmask values in a GCR request, (3) a long last parameter in a GETCONFIG packet, or (4) long values in a request with an invalid format.

Published Mar 2, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-0397: Format string vulnerability in the SetImageInfo function in image.c for ImageMagick before 6.0.2.5 may allo...

Format string vulnerability in the SetImageInfo function in image.c for ImageMagick before 6.0.2.5 may allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a filename argument to convert, which may be called by other web applications.

Published Mar 7, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-0109: Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium an...

Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.

Published Mar 8, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-0083: MySQL MaxDB 7.5.00 for Windows, and possibly earlier versions and other platforms, allows remote attackers...

MySQL MaxDB 7.5.00 for Windows, and possibly earlier versions and other platforms, allows remote attackers to cause a denial of service (application crash) via invalid parameters to the (1) DBMCli_String::ReallocString, (2) DBMCli_String::operator, (3) DBMCli_Buffer::ForceResize, (4) DBMCli_Wizard::InstallDatabase, (5) DBMCli_Devspaces::Complete, (6) DBMWeb_TemplateWizard::askForWriteCountStep5, or (7) DBMWeb_DBMWeb::wizardDB functions, which triggers a null dereference.

Published Mar 17, 2005 · Updated Aug 7, 2024