LiveActive security incident?Get immediate response
CVE archive

July 2005

Browse CVE records published in July 2005, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 286 matching CVEs · Page 5 of 6.

Unknown · CVSS Not scored

CVE-2005-2243: Memory leak in inetinfo.exe in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2...

Memory leak in inetinfo.exe in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1, when Multi Level Admin (MLA) is enabled, allows remote attackers to cause a denial of service (memory consumption) via a large number of Admin Service Tool (AST) logins that fail.

Published Jul 12, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-2221: Multiple SQL injection vulnerabilities in Dragonfly Commerce allows remote attackers to modify SQL statemen...

Multiple SQL injection vulnerabilities in Dragonfly Commerce allows remote attackers to modify SQL statements and possibly execute arbitrary SQL commands via the (1) key parameter to dc_Categoriesview.asp, (2) dc_productslist_Clearance.asp, (3) PID parameter to ratings.asp, (4) dc_Productsview.asp, (5) start, (6) key_mp, (7) searchtype, or (8) psearch parameters to dc_forum_Postslist.asp. NOTE: the vendor has disputed this issue, saying that the error messages arise from invalid category and product numbers. Assuming that this is the case, the issue still satisfies the CVE definition of "exposure.

Published Jul 12, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-2204: Cross-site scripting (XSS) vulnerability in Computer Associates (CA) eTrust SiteMinder 5.5, when the "CSSCh...

Cross-site scripting (XSS) vulnerability in Computer Associates (CA) eTrust SiteMinder 5.5, when the "CSSChecking" parameter is set to "NO," allows remote attackers to inject arbitrary web script or HTML via the (1) PASSWORD or (2) BUFFER parameters to smpwservicescgi.exe, (3) the TARGET parameter to login.fcc, and possibly other vectors.

Published Jul 11, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-2193: SQL injection vulnerability in the user profile edit module in profile.php for PunBB 1.2.5 and earlier allo...

SQL injection vulnerability in the user profile edit module in profile.php for PunBB 1.2.5 and earlier allows remote attackers to execute arbitrary SQL statements via the temp array, which is not initialized before it is used and prevents the attacker-supplied portions of the array from being properly escaped.

Published Jul 10, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-2187: McAfee IntruShield Security Management System allows remote authenticated users to access the "Generate Rep...

McAfee IntruShield Security Management System allows remote authenticated users to access the "Generate Reports" feature and modify alerts by setting the Access option to true, as demonstrated using the (1) fullAccess or (2) fullAccessRight parameter in reports-column-center.jsp, or (3) fullAccess parameter to SystemEvent.jsp.

Published Jul 10, 2005 · Updated Aug 7, 2024