Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29998 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-3343 1 Tkdiff 1 Tkdiff 2026-06-16 4.6 MEDIUM N/A
tkdiff before 4.1.1 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
CVE-2005-3342 1 Norman Ramsey 1 Noweb 2026-06-16 1.2 LOW N/A
noweb 2.10c and earlier allows local users to overwrite arbitrary files via symlink attacks on temporary files in (1) lib/toascii.nw and (2) shell/roff.mm.
CVE-2005-3341 1 Dhis Tools 1 Dns Package 2026-06-16 2.1 LOW N/A
DHIS tools DNS package (dhis-tools-dns) before 5.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files created by (1) register-q.sh and (2) register-p.sh.
CVE-2005-3340 1 New Breed Software 1 Tux Paint 2026-06-16 7.2 HIGH N/A
The tuxpaint-import.sh script in Tux Paint (tuxpaint) 0.9.14 and earlier creates temporary files insecurely, with unknown impact and attack vectors.
CVE-2005-3339 1 Mantis 1 Mantis 2026-06-16 7.2 HIGH N/A
Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors.
CVE-2005-3338 1 Mantis 1 Mantis 2026-06-16 5.0 MEDIUM N/A
Unspecified vulnerability in Mantis before 0.19.3, when using reminders, causes Mantis to display the real email addresses of users.
CVE-2005-3337 1 Mantis 1 Mantis 2026-06-16 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Mantis before 0.19.3 allow remote attackers to inject arbitrary web script or HTML via (1) unknown vectors involving Javascript and (2) mantis/view_all_set.php.
CVE-2005-3336 1 Mantis 1 Mantis 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
CVE-2005-3335 1 Mantis 1 Mantis 2026-06-16 7.5 HIGH N/A
PHP file inclusion vulnerability in bug_sponsorship_list_view_inc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the t_core_path parameter.
CVE-2005-3334 1 Flyspray 1 Flyspray 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php in Flyspray 0.9.7 through 0.9.8 (devel) allows remote attackers to inject arbitrary web script or HTML via the (1) PHPSESSID, (2) task, (3) string, (4) type, (5) serv, (6) due, (7) dev, and (8) sort2 parameters.
CVE-2005-3333 1 Ebase 1 Ebaseweb 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in eBASEweb 3.0 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.
CVE-2005-3332 1 Belchior Foundry 1 Vcard 2026-06-16 7.5 HIGH N/A
PHP remote file include vulnerability in admin/define.inc.php in Belchior Foundry vCard 2.9 allows remote attackers to execute arbitrary PHP code via the match parameter.
CVE-2005-3331 1 Rogers Software Source 1 Mgdiff Patch Viewer 2026-06-16 2.1 LOW N/A
viewpatch in mgdiff 1.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
CVE-2005-3329 1 Rsa 1 Authentication Agent For Web 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in RSA Authentication Agent for Web 5.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the image parameter in a GetPic operation.
CVE-2005-3328 1 Punbb 1 Punbb 2026-06-16 7.5 HIGH N/A
PHP remote file inclusion vulnerability in common.php in PunBB 1.1.2 through 1.1.5 allows remote attackers to execute arbitrary code via the pun_root parameter.
CVE-2005-3327 1 Network Appliance 1 Data Ontap 2026-06-16 7.5 HIGH N/A
Network Appliance Data ONTAP 7.0 and earlier allows iSCSI Initiators to bypass iSCSI authentication via a modified client that skips the Security (Start) mode, as required by the Login Negotiation protocol, and uses Operational mode without proving identity.
CVE-2005-3326 1 Mybulletinboard 1 Mybulletinboard 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in usercp.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the awayday parameter.
CVE-2005-3324 1 Appindex 1 Mwchat 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in chat.php in MWChat 6.8 allows remote attackers to execute arbitrary SQL commands via the username parameter.
CVE-2005-3323 2 Debian, Zope 2 Debian Linux, Zope 2026-06-16 7.5 HIGH N/A
docutils in Zope 2.6, 2.7 before 2.7.8, and 2.8 before 2.8.2 allows remote attackers to include arbitrary files via include directives in RestructuredText functionality.
CVE-2005-3322 2 Squid, Suse 2 Squid, Suse Linux 2026-06-16 5.0 MEDIUM N/A
Unspecified vulnerability in Squid on SUSE Linux 9.0 allows remote attackers to cause a denial of service (crash) via HTTPs (SSL).