LiveActive security incident?Get immediate response
CVE archive

2005 CVE Archive

Browse CVE records published in 2005 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 4627 matching CVEs · Page 5 of 93.

Unknown · CVSS Not scored

CVE-2005-4276: Westell Versalink 327W allows remote attackers to cause a denial of service (device crash) via an IP packet...

Westell Versalink 327W allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LanD). NOTE: the provenance of this issue is unknown; the details are obtained solely from third party information.

Published Dec 16, 2005 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2005-1673: Multiple SQL injection vulnerabilities in Help Center Live allow remote attackers to execute arbitrary SQL...

Multiple SQL injection vulnerabilities in Help Center Live allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to index.php, (2) tid parameter to view.php, fid parameter to (3) download.php or (4) chat_download.php, (5) status parameter to icon.php, TICKET_tid parameter to (6) index.php or (7) view.php.

Published May 19, 2005 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2005-4660: Race condition in IPCop (aka IPCop Firewall) before 1.4.10 might allow local users to overwrite system conf...

Race condition in IPCop (aka IPCop Firewall) before 1.4.10 might allow local users to overwrite system configuration files and gain privileges by replacing a backup archive during the time window when the archive is owned by "nobody" but not yet encrypted, then executing ipcoprscfg to restore from this backup.

Published Jan 16, 2006 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2005-2044: Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.3 and 1.5 RC 1 allow remote attackers to...

Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.3 and 1.5 RC 1 allow remote attackers to inject arbitrary web script or HTML via the (1) show_course parameter to browse.php, (2) subject parameter to contact.php, (3) cid parameter to content.php, (4) l parameter to inbox/send_message.php, the (5) search, (6) words, (7) include, (8) find_in, (9) display_as, or (10) search parameter to search.php, the (11) submit, (12) query, or (13) field parameter to tile.php, the (14) us parameter to forum/subscribe_forum.php, or the (15) roles[], (16) status, (17) submit, or (18) reset_filter parameters to directory.php.

Published Jun 22, 2005 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2005-1676: Multiple cross-site scripting (XSS) vulnerabilities in Groove Mobile Workspace in Groove Virtual Office bef...

Multiple cross-site scripting (XSS) vulnerabilities in Groove Mobile Workspace in Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 allow remote attackers to inject arbitrary web script or HTML via the (1) picture columns embedded within SharePoint lists or (2) drop-down menus in a SharePoint list.

Published May 25, 2005 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2005-2019: ipfw in FreeBSD 5.4, when running on Symmetric Multi-Processor (SMP) or Uni Processor (UP) systems with the...

ipfw in FreeBSD 5.4, when running on Symmetric Multi-Processor (SMP) or Uni Processor (UP) systems with the PREEMPTION kernel option enabled, does not sufficiently lock certain resources while performing table lookups, which can cause the cache results to be corrupted during multiple concurrent lookups, allowing remote attackers to bypass intended access restrictions.

Published Jun 30, 2005 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2005-4339: Cross-site scripting (XSS) vulnerability in Blackboard Learning and Community Portal System in Academic Sui...

Cross-site scripting (XSS) vulnerability in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to inject arbitrary web script or HTML via the context parameter to announcement.pl, which is reflected in the resulting page.

Published Dec 17, 2005 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2005-4649: Multiple cross-site scripting (XSS) vulnerabilities in Advanced Guestbook 2.2 and 2.3.1 allow remote attack...

Multiple cross-site scripting (XSS) vulnerabilities in Advanced Guestbook 2.2 and 2.3.1 allow remote attackers to inject arbitrary web script or HTML via (1) the entry parameter in index.php and (2) the gb_id parameter in comment.php. NOTE: The index.php/entry vector might be resultant from CVE-2005-1548.

Published Jan 13, 2006 · Updated Sep 16, 2024