LiveActive security incident?Get immediate response
CVE archive

September 2005

Browse CVE records published in September 2005, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 313 matching CVEs · Page 4 of 7.

Unknown · CVSS Not scored

CVE-2005-2949: pam_per_user before 0.4 does not verify if the user name changes between authentication attempts and uses t...

pam_per_user before 0.4 does not verify if the user name changes between authentication attempts and uses the same subrequest handle, which allows remote attackers or local users to login as other users by using certain applications that allow the username to be changed during authentication, such as /bin/login.

Published Sep 16, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-3020: Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inj...

Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to css.php, (2) redirect parameter to index.php, (3) email parameter to user.php, (4) goto parameter to language.php, (5) orderby parameter to modlog.php, and the (6) hex, (7) rgb, or (8) expandset parameter to template.php.

Published Sep 21, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-3022: Multiple SQL injection vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to execute arb...

Multiple SQL injection vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, (2) userid parameter to user.php, (3) calendar parameter to admincalendar.php, (4) cronid parameter to cronlog.php, (5) usergroupid parameter to email.php, (6) help parameter to help.php, (7) rvt parameter to language.php, (8) keep parameter to phrase.php, or (9) updateprofilepic parameter to usertools.php.

Published Sep 21, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-2915: ezconfig.asp in Linksys WRT54G router 3.01.03, 3.03.6, non-default configurations of 2.04.4, and possibly o...

ezconfig.asp in Linksys WRT54G router 3.01.03, 3.03.6, non-default configurations of 2.04.4, and possibly other versions, uses weak encryption (XOR encoding with a fixed byte mask) for configuration information, which could allow attackers to decrypt the information and possibly re-encrypt it in conjunction with CVE-2005-2914.

Published Sep 14, 2005 · Updated Aug 7, 2024