Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29998 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-1093 1 Popup Plus Plugin 1 Popup Plus Plugin For Miranda Im 2026-06-16 7.5 HIGH N/A
Buffer overflow in the PopUp Plus 2.0.3.8 plugin for Miranda IM, with "Use SmileyAdd Setting" enabled, allows remote attackers to execute arbitrary code.
CVE-2005-1092 1 Light Speed Technology 1 Deluxeftp 2026-06-16 7.2 HIGH N/A
Lightspeed DeluxeFTP 6.01 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges.
CVE-2005-1091 1 Maxthon 1 Maxthon 2026-06-16 7.5 HIGH N/A
Maxthon 1.2.0 and 1.2.1 allows remote attackers to bypass the security ID and use restricted plugin API functions via script that includes the max.src file into the source page.
CVE-2005-1090 1 Maxthon 1 Maxthon 2026-06-16 6.4 MEDIUM N/A
Directory traversal vulnerability in the readFile and writeFile API for Maxthon 1.2.0 and 1.2.1 allows remote attackers to read or write arbitrary files.
CVE-2005-1089 1 Dc\+\+ 1 Dc\+\+ 2026-06-16 5.0 MEDIUM N/A
Unknown vulnerability in DC++ before 0.674 allows attackers to append data to arbitrary files.
CVE-2005-1088 1 Dameware Development 2 Mini Remote Control, Nt Utilities 2026-06-16 7.2 HIGH N/A
Unknown vulnerability in DameWare NT Utilities 4.8 and earlier, and Mini Remote Control 4.8 and earlier, allows local users to gain additional rights.
CVE-2005-1087 1 An 1 An-httpd 2026-06-16 6.4 MEDIUM N/A
CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide entries in the logfile, and possibly read files using an injected type command, via CRLF sequences in an HTTP request.
CVE-2005-1086 1 An 1 An-httpd 2026-06-16 6.4 MEDIUM N/A
Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via an HTTP request with a long User-Agent header.
CVE-2005-1085 1 Aewebworks 1 Aedating 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the control panel in aeDating 3.2 allows remote attackers to inject arbitrary web script or HTML.
CVE-2005-1084 1 Aewebworks 1 Aedating 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in sdating.php in aeDating 3.2 allows remote attackers to execute arbitrary SQL commands files via the event parameter.
CVE-2005-1083 1 Aewebworks 1 Aedating 2026-06-16 5.0 MEDIUM N/A
index.php in aeDating 3.2 allows remote attackers to include arbitrary files via the skin parameter.
CVE-2005-1082 1 Azerbaijan Development Group 1 Azdgdating 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in AzDGDatingPlatinum 1.1.0 allows remote attackers to execute arbitrary SQL commands via (1) the id parameter to view.php or (2) the from parameter to members/index.php.
CVE-2005-1081 1 Azerbaijan Development Group 1 Azdgdating 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in view.php in AzDGDatingPlatinum 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CVE-2005-1080 1 Sun 1 Sdk 2026-06-16 5.0 MEDIUM N/A
Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in filenames in a .jar file.
CVE-2005-1079 1 Mike De Boer 1 Zoom Media Gallery 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index.php for zOOm Media Gallery 2.1.2 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
CVE-2005-1078 1 Xampp 1 Apache Distribution 2026-06-16 7.5 HIGH N/A
XAMPP 1.4.x has multiple default or null passwords, which allows attackers to gain privileges.
CVE-2005-1077 1 Xampp 1 Apache Distribution 2026-06-16 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.4.x allow remote attackers to inject arbitrary web script or HTML via (1) cds.php, (2) Guestbook-EN.pl, or (3) phonebook.php.
CVE-2005-1076 1 Webct 1 Webct 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the discussion board functionality for WebCT Campus Edition 4.1 allows remote attackers to inject arbitrary web script or HTML via the message field.
CVE-2005-1075 1 Radscripts 1 Radbids 2026-06-16 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in RadScripts RadBids Gold 2 allow remote attackers to inject arbitrary web script or HTML via (1) the farea parameter to faq.php or the (2) cat, (3) order, or (4) area parameters to index.php.
CVE-2005-1074 1 Radscripts 1 Radbids 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index.php for RadScripts RadBids Gold 2 allows remote attackers to execute arbitrary SQL commands via the mode parameter.