LiveActive security incident?Get immediate response
CVE archive

July 2005

Browse CVE records published in July 2005, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 286 matching CVEs · Page 4 of 6.

Unknown · CVSS Not scored

CVE-2005-2225: Microsoft MSN Messenger allows remote attackers to cause a denial of service via a plaintext message contai...

Microsoft MSN Messenger allows remote attackers to cause a denial of service via a plaintext message containing the ".pif" string, which is interpreted as a malicious file extension and causes users to be kicked from a group conversation. NOTE: it has been reported that Gaim is also affected, so this may be an issue in the protocol or MSN servers.

Published Jul 12, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-2266: Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a...

Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.

Published Jul 13, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-2267: Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by us...

Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash and QuickTime to open a javascript: URL, which is run in the context of the previous page, and may lead to code execution if the standalone application loads a privileged chrome: URL.

Published Jul 13, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-2241: Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(...

Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 does not quickly time out Realtime Information Server Data Collection (RISDC) sockets, which results in a "resource leak" that allows remote attackers to cause a denial of service (memory and connection consumption) in RisDC.exe.

Published Jul 12, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-2263: The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers...

The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the context of another domain by forcing a page navigation after the install method has been called, which causes the callback to be run in the context of the new page and results in a same origin violation.

Published Jul 13, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-2269: Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated type...

Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").

Published Jul 13, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-2220: Dragonfly Commerce allows remote attackers to change a product price by modifying the x_DragonflyCartProduc...

Dragonfly Commerce allows remote attackers to change a product price by modifying the x_DragonflyCartProductPrice hidden field to (1) dc_Categorieslist.asp, (2) dc_Categoriesview.asp, (3) dc_productslist.asp, and (4) dc_productslist_Clearance.asp. NOTE: the vendor has disputed this issue, saying that "Dragonfly Commerce does not allow for editing prices nor does it allow for viewing information about clients stored in the database except by the store owner and authorized staff as appointed in the store administration." However, SecurityTracker claims that they have been able to confirm the problem

Published Jul 12, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-2260: The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does n...

The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does not properly distinguish between user-generated events and untrusted synthetic events, which makes it easier for remote attackers to perform dangerous actions that normally could only be performed manually by the user.

Published Jul 13, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-2259: The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANe...

The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Software, and (4) MakeBid Reverse Auction allows remote attackers to execute arbitrary code via shell metacharacters in the DISPCLOSED parameter.

Published Jul 13, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-2244: The aupair service (aupair.exe) in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4...

The aupair service (aupair.exe) in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to execute arbitrary code or corrupt memory via crafted packets that trigger a memory allocation failure and lead to a buffer overflow.

Published Jul 12, 2005 · Updated Aug 7, 2024