LiveActive security incident?Get immediate response
CVE archive

October 2005

Browse CVE records published in October 2005, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 300 matching CVEs · Page 3 of 6.

Unknown · CVSS Not scored

CVE-2005-3317: Multiple stack-based buffer overflows in ZipGenius 5.5.1.468 and 6.0.2.1041, and other versions before 6.0....

Multiple stack-based buffer overflows in ZipGenius 5.5.1.468 and 6.0.2.1041, and other versions before 6.0.2.1050, allow remote attackers to execute arbitrary code via (1) a ZIP archive that contains a file with a long filename, which is not properly handled by (a) zipgenius.exe, (b) zg.exe, (c) zgtips.dll, and (d) contmenu.dll; (2) a long original name in a (a) UUE, (b) XXE, or (c) MIM file, which is not properly handled by zipgenius.exe; or (3) an ACE archive with a file with a long filename, which is not properly handled by unacev2.dll.

Published Oct 27, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-3325: Multiple SQL injection vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases...

Multiple SQL injection vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 and (2) base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.2, and unspecified other console scripts in these products, allow remote attackers to execute arbitrary SQL commands via the sig[1] parameter and possibly other parameters.

Published Oct 27, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-3306: Cross-site scripting (XSS) vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to inject...

Cross-site scripting (XSS) vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the user parameter in a profile operation, a different vulnerability than CVE-2005-2814. NOTE: it is possible that this XSS is a resultant vulnerability of CVE-2005-3307.

Published Oct 25, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-3315: Multiple SQL injection vulnerabilities in Novell ZENworks Patch Management 6.x before 6.2.2.181 allow remot...

Multiple SQL injection vulnerabilities in Novell ZENworks Patch Management 6.x before 6.2.2.181 allow remote attackers to execute arbitrary SQL commands via the (1) Direction parameter to computers/default.asp, and the (2) SearchText, (3) StatusFilter, and (4) computerFilter parameters to reports/default.asp.

Published Oct 30, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-3305: Multiple SQL injection vulnerabilities in Nuked Klan 1.7 allow remote attackers to execute arbitrary SQL co...

Multiple SQL injection vulnerabilities in Nuked Klan 1.7 allow remote attackers to execute arbitrary SQL commands via the (1) forum_id or (2) thread_id parameter in the Forum file, (3) the link_id in the Links file, (4) the artid parameter in the Sections file, and (5) the dl_id parameter in the Download file.

Published Oct 25, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-3300: The register_globals emulation layer in grab_globals.php for phpMyAdmin before 2.6.4-pl3 does not perform s...

The register_globals emulation layer in grab_globals.php for phpMyAdmin before 2.6.4-pl3 does not perform safety checks on values in the _FILES array for uploaded files, which allows remote attackers to include arbitrary files by using direct requests to library scripts that do not use grab_globals.php, then modifying certain configuration values for the theme.

Published Oct 23, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-3275: The NAT code (1) ip_nat_proto_tcp.c and (2) ip_nat_proto_udp.c in Linux kernel 2.6 before 2.6.13 and 2.4 be...

The NAT code (1) ip_nat_proto_tcp.c and (2) ip_nat_proto_udp.c in Linux kernel 2.6 before 2.6.13 and 2.4 before 2.4.32-rc1 incorrectly declares a variable to be static, which allows remote attackers to cause a denial of service (memory corruption) by causing two packets for the same protocol to be NATed at the same time, which leads to memory corruption.

Published Oct 20, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-3267: Integer overflow in Skype client before 1.4.x.84 on Windows, before 1.3.x.17 on Mac OS, before 1.2.x.18 on...

Integer overflow in Skype client before 1.4.x.84 on Windows, before 1.3.x.17 on Mac OS, before 1.2.x.18 on Linux, and 1.1.x.6 and earlier allows remote attackers to cause a denial of service (crash) via crafted network data with a large Object Counter value, which leads to a resultant heap-based buffer overflow.

Published Oct 27, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-3233: Multiple interpretation error in unspecified versions of Trustix Antivirus allows remote attackers to bypas...

Multiple interpretation error in unspecified versions of Trustix Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

Published Oct 14, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-3227: Multiple interpretation error in unspecified versions of UNA Antivirus allows remote attackers to bypass vi...

Multiple interpretation error in unspecified versions of UNA Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

Published Oct 14, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-3220: Multiple interpretation error in unspecified versions of Norman Virus Control Antivirus allows remote attac...

Multiple interpretation error in unspecified versions of Norman Virus Control Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

Published Oct 14, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-3217: Multiple interpretation error in unspecified versions of Symantec Antivirus allows remote attackers to bypa...

Multiple interpretation error in unspecified versions of Symantec Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

Published Oct 14, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-3228: Multiple interpretation error in unspecified versions of Ikarus AntiVirus allows remote attackers to bypass...

Multiple interpretation error in unspecified versions of Ikarus AntiVirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

Published Oct 14, 2005 · Updated Aug 7, 2024