LiveActive security incident?Get immediate response
CVE archive

May 2005

Browse CVE records published in May 2005, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 428 matching CVEs · Page 3 of 9.

Unknown · CVSS Not scored

CVE-2005-1770: Buffer overflow in the Aavmker4 device driver in Avast!

Buffer overflow in the Aavmker4 device driver in Avast! Antivirus 4.6 and possibly other versions allows local users to cause a denial of service (system crash) and possibly execute arbitrary code via certain signals combined with crafted input.

Published May 31, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-1754: JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary...

JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary files via a full pathname in the argument to the Download parameter. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products.

Published May 21, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-1783: BookReview beta 1.0 allows remote attackers to obtain the path of the web server via certain parameters to...

BookReview beta 1.0 allows remote attackers to obtain the path of the web server via certain parameters to search.htm, possibly due to a search[string] parameter with a missing value or an incorrect submit[type] value, which reveals the path in the resulting error message. NOTE: it is not clear whether BookReview is available to the public. If not, then it should not be included in CVE.

Published May 31, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-1753: ReadMessage.jsp in JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers...

ReadMessage.jsp in JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to view other users' e-mail attachments via a direct request to /mailboxesdir/username@domainname. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products.

Published May 21, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-1693: Integer overflow in Computer Associates Vet Antivirus library, as used by CA InoculateIT 6.0, eTrust Antivi...

Integer overflow in Computer Associates Vet Antivirus library, as used by CA InoculateIT 6.0, eTrust Antivirus r6.0 through 7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, BrightStor ARCserve Backup (BAB) r11.1, Vet Antivirus, Zonelabs ZoneAlarm Security Suite, and ZoneAlarm Antivirus, allows remote attackers to gain privileges via a compressed VBA directory with a project name length of -1, which leads to a heap-based buffer overflow.

Published May 24, 2005 · Updated Aug 7, 2024