Vulnerabilities (CVE)

Total 374378 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-3543 1 Phorum 1 Phorum 2026-06-16 6.8 MEDIUM N/A
SQL injection vulnerability in search.php in Phorum 5.0.0alpha through 5.0.20, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the forum_ids parameter.
CVE-2005-3540 1 Petris 1 Petris 2026-06-16 7.5 HIGH N/A
Buffer overflow in petris before 1.0.1 allows remote attackers to execute arbitrary code via unspecified attack vectors.
CVE-2005-3539 1 Hylafax 1 Hylafax 2026-06-16 7.5 HIGH N/A
Multiple eval injection vulnerabilities in HylaFAX 4.2.3 and earlier allow remote attackers to execute arbitrary commands via (1) the notify script in HylaFAX 4.2.0 to 4.2.3 and (2) crafted CallID parameters to the faxrcvd script in HylaFAX 4.2.2 and 4.2.3.
CVE-2005-3538 1 Ifax Solutions 1 Hylafax 2026-06-16 7.5 HIGH N/A
hfaxd in HylaFAX 4.2.3, when PAM support is disabled, accepts arbitrary passwords, which allows remote attackers to gain privileges.
CVE-2005-3537 1 Phpbb Group 1 Phpbb 2026-06-16 5.0 MEDIUM N/A
A "missing request validation" error in phpBB 2 before 2.0.18 allows remote attackers to edit private messages of other users, probably by modifying certain parameters or other inputs.
CVE-2005-3536 1 Phpbb Group 1 Phpbb 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in phpBB 2 before 2.0.18 allows remote attackers to execute arbitrary SQL commands via the topic type.
CVE-2005-3535 1 Ketm 1 Ketm 2026-06-16 7.5 HIGH N/A
Buffer overflow in KETM 0.0.6 allows local users to execute arbitrary code via unknown vectors.
CVE-2005-3534 1 Wouter Verhelst 1 Nbd 2026-06-16 7.5 HIGH N/A
Buffer overflow in the Network Block Device (nbd) server 2.7.5 and earlier, and 2.8.0 through 2.8.2, allows remote attackers to execute arbitrary code via a large request, which is written past the end of the buffer because nbd does not account for memory taken by the reply header.
CVE-2005-3533 1 Osh 1 Osh 2026-06-16 7.2 HIGH N/A
Buffer overflow in OSH before 1.7-15 allows local users to execute arbitrary code via a long current working directory and filename.
CVE-2005-3532 1 Double Precision Incorporated 1 Courier Mail Server 2026-06-16 7.5 HIGH N/A
authpam.c in courier-authdaemon for Courier Mail Server 0.37.3 through 0.52.1, when using pam_tally, does not call the pam_acct_mgmt function to verify that access should be granted, which allows attackers to authenticate to the server using accounts that have been disabled.
CVE-2005-3531 1 Miklos Szeredi 1 Fuse 2026-06-16 2.1 LOW N/A
fusermount in FUSE before 2.4.1, if installed setuid root, allows local users to corrupt /etc/mtab and possibly modify mount options by performing a mount over a directory whose name contains certain special characters.
CVE-2005-3530 1 Antville 1 Antville 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Antville 1.1 allows remote attackers to inject arbitrary web script or HTML via the notfound.skin error document.
CVE-2005-3529 1 Tiki 1 Tikiwiki Cms\/groupware 2026-06-16 5.0 MEDIUM N/A
tiki-view_forum_thread.php in TikiWiki 1.9.0 through 1.9.2 allows remote attackers to obtain the installation path via an invalid topics_sort_mode parameter, possibly related to an SQL injection vulnerability.
CVE-2005-3528 1 Tiki 1 Tikiwiki Cms\/groupware 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in tiki-view_forum_thread.php in TikiWiki 1.9.0 through 1.9.2 allows remote attackers to inject arbitrary web script or HTML via the topics_offset parameter.
CVE-2005-3527 1 Linux 1 Linux Kernel 2026-06-16 4.0 MEDIUM N/A
Race condition in do_coredump in signal.c in Linux kernel 2.6 allows local users to cause a denial of service by triggering a core dump in one thread while another thread has a pending SIGSTOP.
CVE-2005-3526 1 Ipswitch 1 Ipswitch Collaboration Suite 2026-06-16 6.5 MEDIUM N/A
Buffer overflow in the IMAP daemon in Ipswitch Collaboration Suite 2006.02 and earlier allows remote authenticated users to execute arbitrary code via a long FETCH command.
CVE-2005-3525 1 Adobe 1 Shockwave Player 2026-06-16 9.3 HIGH N/A
Stack-based buffer overflow in an ActiveX control for the installer for Adobe Macromedia Shockwave Player 10.1.0.11 and earlier allows remote attackers to execute arbitrary code via crafted large values for unspecified parameters.
CVE-2005-3524 1 Linux-ftpd-ssl 1 Linux-ftpd-ssl 2026-06-16 10.0 HIGH N/A
Buffer overflow in the SSL-ready version of linux-ftpd (linux-ftpd-ssl) 0.17 allows remote attackers to execute arbitrary code by creating a long directory name, then executing the XPWD command.
CVE-2005-3523 1 Gpsdrive 1 Gpsdrive 2026-06-16 7.5 HIGH N/A
Format string vulnerability in friendsd2 in GpsDrive allows remote attackers to execute arbitrary code via the dir (direction) field.
CVE-2005-3522 1 Adventnet 1 Manageengine Netflow Analyzer 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.jsp in ManageEngine Netflow Analyzer 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the grDisp parameter.