Vulnerabilities (CVE)

Total 398493 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-1321 1 Horde 1 Vaction 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Horde Vacation module before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
CVE-2005-1320 1 Horde 1 Mnemo 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Horde Mnemo Note Manager before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
CVE-2005-1319 1 Horde 1 Imp 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Horde IMP Webmail client before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
CVE-2005-1318 1 Horde 1 Forwards 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Horde Forwards E-Mail Forwarding Manager before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
CVE-2005-1317 1 Horde 1 Chora 2026-06-16 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Horde Chora module before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
CVE-2005-1316 1 Horde 1 Accounts 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Horde Accounts module before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
CVE-2005-1315 1 Horde 1 Turba 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Horde Turba module before 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
CVE-2005-1314 1 Horde 1 Kronolith 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Horde Kronolith module before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
CVE-2005-1313 1 Horde 1 Passwd 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Horde Passwd module before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
CVE-2005-1312 1 Yappa-ng 1 Yappa-ng 2026-06-16 7.5 HIGH N/A
PHP remote file inclusion vulnerability in Yappa-NG before 2.3.2 allows remote attackers to execute arbitrary PHP code via unknown vectors.
CVE-2005-1311 1 Yappa-ng 1 Yappa-ng 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Yappa-NG before 2.3.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
CVE-2005-1310 1 Eaden Mckee 1 Bblog 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in bBlog 0.7.4 allows remote attackers to execute arbitrary SQL commands via the postid parameter.
CVE-2005-1309 1 Eaden Mckee 1 Bblog 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in bBlog 0.7.4 allows remote attackers to inject arbitrary web script or HTML via the (1) entry title field or (2) comment body text.
CVE-2005-1308 1 Inter7 1 Sqwebmail 2026-06-16 7.5 HIGH N/A
SqWebMail allows remote attackers to inject arbitrary web script or HTML via CRLF sequences in the redirect parameter followed by the desired script or HTML.
CVE-2005-1307 2 Adobe, Apple 2 Version Cue, Mac Os X 2026-06-16 7.2 HIGH N/A
The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the productname.sh script, which allows local users to execute arbitrary code by copying and calling the scripts from a user-controlled directory.
CVE-2005-1306 1 Adobe 2 Acrobat, Acrobat Reader 2026-06-16 5.0 MEDIUM 7.5 HIGH
The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulnerability."
CVE-2005-1305 1 Hyper.cgi 1 Hyper.cgi 2026-06-16 5.0 MEDIUM N/A
The hyper.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.
CVE-2005-1304 1 Citat.pl 1 Citat.pl 2026-06-16 7.5 HIGH N/A
The citat.pl script allows remote attackers to execute arbitrary files via shell metacharacters in the argument.
CVE-2005-1303 1 Citat.pl 1 Citat.pl 2026-06-16 7.5 HIGH N/A
The citat.pl script allows remote attackers to read arbitrary files via a full pathname in the argument.
CVE-2005-1302 1 Swsoft 1 Confixx 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in Confixx 3.08 and earlier allows remote attackers to execute arbitrary SQL commands via the "change user" field.