LiveActive security incident?Get immediate response
CVE archive

October 2005

Browse CVE records published in October 2005, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 300 matching CVEs · Page 5 of 6.

Unknown · CVSS Not scored

CVE-2005-3212: Multiple interpretation error in unspecified versions of NOD32 Antivirus allows remote attackers to bypass...

Multiple interpretation error in unspecified versions of NOD32 Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

Published Oct 14, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-3214: Multiple interpretation error in unspecified versions of Avast Antivirus allows remote attackers to bypass...

Multiple interpretation error in unspecified versions of Avast Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

Published Oct 14, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-3232: Multiple interpretation error in unspecified versions of TheHacker allows remote attackers to bypass virus...

Multiple interpretation error in unspecified versions of TheHacker allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

Published Oct 14, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-3182: Buffer overflow in the HTTP management interface for GFI MailSecurity 8.1 allows remote attackers to execut...

Buffer overflow in the HTTP management interface for GFI MailSecurity 8.1 allows remote attackers to execute arbitrary code via long headers such as (1) Host and (2) Accept in HTTP requests. NOTE: the vendor suggests that this issues is "in an underlying Microsoft technology" which, if true, could mean that the overflow affects other products as well.

Published Oct 20, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-3181: The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is ena...

The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which prevents the memory from being tracked by AUDITSYSCALL code and leads to a memory leak that allows attackers to cause a denial of service (memory consumption).

Published Oct 11, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-3131: Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1...

Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to blank.html, or the createdataCX parameter to (2) calendar_d.html, (3) calendar_m.html, or (4) calendar_w.html.

Published Oct 4, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-3164: The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosmine...

The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body data" is used for a different request, possibly related to Java Servlet pages.

Published Oct 6, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-3133: Multiple directory traversal vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and p...

Multiple directory traversal vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to (1) delete arbitrary files or directories via a relative path to the id parameter to logout.html or (2) include arbitrary PHP files or other files via the helpid parameter to help.html.

Published Oct 4, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-3153: login.php in myBloggie 2.1.3 beta and earlier allows remote attackers to bypass a whitelist regular express...

login.php in myBloggie 2.1.3 beta and earlier allows remote attackers to bypass a whitelist regular expression and conduct SQL injection attacks via a username parameter with SQL after a null character, which causes the whitelist check to succeed but injects the SQL into a query string, a different vulnerability than CVE-2005-2838. NOTE: it is possible that this is actually a bug in PHP code, in which case this should not be treated as a myBloggie vulnerability.

Published Oct 5, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-3152: Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.3 allow remote attackers to inject arbi...

Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the redir parameter to (1) cart.php or (2) index.php, or (3) the searchStr parameter in a viewCat action to index.php. Note: vectors (1) and (2) were later reported to affect 3.0.7-pl1.

Published Oct 5, 2005 · Updated Aug 7, 2024