Vulnerabilities (CVE)

Total 372505 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-0433 1 Francisco Burzi 1 Php-nuke 2026-06-16 5.0 MEDIUM N/A
Php-Nuke 7.5 allows remote attackers to determine the full path of the web server via invalid or missing arguments to (1) db.php, (2) mainfile.php, (3) Downloads/index.php, or (4) Web_Links/index.php, which lists the path in a PHP error message.
CVE-2005-0432 1 Bea 1 Weblogic Server 2026-06-16 5.0 MEDIUM N/A
BEA WebLogic Server 7.0 Service Pack 5 and earlier, and 8.1 Service Pack 3 and earlier, generates different login exceptions that suggest why an authentication attempt fails, which makes it easier for remote attackers to guess passwords via brute force attacks.
CVE-2005-0431 1 Barracuda Networks 1 Barracuda Spam Firewall 2026-06-16 7.5 HIGH N/A
Barracuda Spam Firewall 3.1.10 and earlier does not restrict the domains that white-listed domains can send mail to, which allows members of white-listed domains to use Barracuda as an open mail relay for spam.
CVE-2005-0430 1 Id Software 1 Quake 3 Engine 2026-06-16 5.0 MEDIUM N/A
The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash the server via a long infostring, possibly triggering a buffer overflow.
CVE-2005-0429 1 Jelsoft 1 Vbulletin 2026-06-16 5.0 MEDIUM N/A
Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled, allows remote attackers to execute inject arbitrary PHP commands via the comma parameter.
CVE-2005-0428 1 Powerdns 1 Powerdns 2026-06-16 5.0 MEDIUM N/A
The DNSPacket::expand method in dnspacket.cc in PowerDNS before 2.9.17 allows remote attackers to cause a denial of service by sending a random stream of bytes.
CVE-2005-0427 1 Gentoo 1 Webmin 2026-06-16 5.0 MEDIUM N/A
The ebuild of Webmin before 1.170-r3 on Gentoo Linux includes the encrypted root password in the miniserv.users file when building a tbz2 of the webmin package, which allows remote attackers to obtain and possibly crack the encrypted password.
CVE-2005-0426 1 Sun 2 Solaris, Sunos 2026-06-16 5.0 MEDIUM N/A
Unknown vulnerability in Solaris 8 and 9 allows remote attackers to cause a denial of service (panic) via "Heavy UDP Usage" that triggers a NULL dereference.
CVE-2005-0425 1 Ibm 1 Websphere Application Server 2026-06-16 5.0 MEDIUM N/A
Unknown vulnerability in IBM Websphere Application Server 5.0, 5.1, and 6.0 when running on Windows, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via a crafted URL that causes the page to be processed by the file serving servlet instead of the JSP engine.
CVE-2005-0424 1 Aspjar 1 Aspjar Guestbook 2026-06-16 5.0 MEDIUM N/A
Unknown vulnerability in the delete.asp program in certain versions of ASPjar Guestbook allows remote attackers to delete messages. NOTE: there is insufficient information to know if this is the same issue as CVE-2002-1730.
CVE-2005-0423 1 Aspjar 1 Aspjar Guestbook 2026-06-16 5.0 MEDIUM N/A
SQL injection vulnerability in login.asp in ASPjar Guestbook allows remote attackers to execute arbitrary SQL commands via the password field.
CVE-2005-0422 1 Delphiturk 1 Codebank 2026-06-16 2.1 LOW N/A
DelphiTurk CodeBank (aka KodBank) 3.1 and earlier stores usernames and passwords in the Codebank registry key, which allows local users to gain privileges.
CVE-2005-0421 1 Delphiturk 1 Delphiturk Ftp 2026-06-16 2.1 LOW N/A
DelphiTurk FTP 1.0 stores usernames and passwords in the profile.dat file, which allows local users to gain privileges.
CVE-2005-0420 1 Microsoft 1 Exchange Server 2026-06-16 5.8 MEDIUM N/A
Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login via a link to the owalogon.asp application.
CVE-2005-0419 1 3com 1 3cserver 2026-06-16 7.5 HIGH N/A
Multiple heap-based buffer overflows in 3Com 3CServer allow remote authenticated users to execute arbitrary code via long FTP commands, as demonstrated using the STAT command.
CVE-2005-0418 1 Sun 1 J2se 2026-06-16 7.5 HIGH N/A
Argument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06, on Mac OS X, allows untrusted applications to gain privileges via the value parameter of a property tag in a JNLP file. NOTE: it is highly likely that this item will be MERGED with CVE-2005-0836.
CVE-2005-0417 1 Ibm 1 Db2 Universal Database 2026-06-16 10.0 HIGH N/A
Unknown "high risk" vulnerability in DB2 Universal Database 8.1 and earlier has unknown impact and attack vectors. NOTE: due to the delayed disclosure of details for this issue, this candidate may be SPLIT in the future. In addition, this may be a duplicate of other issues as reported by the vendor.
CVE-2005-0416 1 Microsoft 7 Windows 2000, Windows 2003 Server, Windows 98 and 4 more 2026-06-16 7.5 HIGH N/A
The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allows remote attackers to execute arbitrary code via the AnimationHeaderBlock length field, which leads to a stack-based buffer overflow.
CVE-2005-0415 1 Ulrik Petersen 1 Emdros Database Engine 2026-06-16 5.0 MEDIUM N/A
Multiple memory leaks in the MQL parser in Emdros before 1.1.22 allow remote attackers to cause a denial of service (memory consumption) via malformed MQL statements.
CVE-2005-0414 1 Mercuryboard 1 Mercuryboard 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in post.php for MercuryBoard 1.1.1 allows remote attackers to execute arbitrary SQL commands via a reply post action for index.php with (1) the t parameter or (2) the qu parameter.