Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,996 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,157 results · page 311 of 344
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2005-4085 | Buffer overflow in BlueCoat (a) WinProxy before 6.1a and (b) the web console access functionality in ProxyAV before 2.4.2.3 allows remote attackers to execute arbitrary code via a long Host: header. | EXPLOIT ×2 ✓HIGH 7.5EPSS 65.9% | 31 December 2005 |
| CVE-2005-3653 | Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length… | HIGH 10.0EPSS 18.6% | 31 December 2005 |
| CVE-2005-3539 | Multiple eval injection vulnerabilities in HylaFAX 4.2.3 and earlier allow remote attackers to execute arbitrary commands via (1) the notify script in HylaFAX 4.2.0 to 4.2.3 and (2) crafted CallID parameters to the faxrcvd script in HylaFAX 4.2.2 and… | EXPLOIT ✓HIGH 7.5EPSS 12.7% | 31 December 2005 |
| CVE-2005-3525 | Stack-based buffer overflow in an ActiveX control for the installer for Adobe Macromedia Shockwave Player 10.1.0.11 and earlier allows remote attackers to execute arbitrary code via crafted large values for unspecified parameters. | HIGH 9.3EPSS 19.7% | 31 December 2005 |
| CVE-2005-3357 | mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a… | MEDIUM 5.4EPSS 24.3% | 31 December 2005 |
| CVE-2005-2340 | Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a crafted (1) QuickTime Image File (QTIF), (2) PICT, or (3) JPEG format image with a long data field. | EXPLOIT ✓HIGH 7.5EPSS 25.5% | 31 December 2005 |
| CVE-2005-1939 | Directory traversal vulnerability in Ipswitch WhatsUp Small Business 2004 allows remote attackers to read arbitrary files via ".." (dot dot) sequences in a request to the Report service (TCP 8022). | EXPLOIT ✓MEDIUM 5.0EPSS 63.6% | 31 December 2005 |
| CVE-2005-1924 | The G/PGP (GPG) Plugin 2.1 and earlier for Squirrelmail allow remote authenticated users to execute arbitrary commands via shell metacharacters in (1) the fpr parameter to the deleteKey function in gpg_keyring.php, as called by (a) import_key_file.php,… | EXPLOIT ×2 ✓HIGH 9.3EPSS 10.3% | 31 December 2005 |
| CVE-2005-4573 | PHP remote file include vulnerability in plog-admin-functions.php in Plogger Beta 2 allows remote attackers to execute arbitrary code via a URL in the config[basedir] parameter. | EXPLOIT ✓HIGH 7.5EPSS 11.7% | 29 December 2005 |
| CVE-2005-4560 | The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows… | EXPLOIT ✓HIGH 7.5EPSS 86.1% | 28 December 2005 |
| CVE-2005-4556 | PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, when register_globals is enabled, allows remote attackers to include arbitrary local and remote PHP… | EXPLOIT ×2 ✓HIGH 7.5EPSS 10.6% | 28 December 2005 |
| CVE-2005-4504 | The khtml::RenderTableSection::ensureRows function in KHTMLParser in Apple Mac OS X 10.4.3 and earlier, as used by Safari and TextEdit, allows remote attackers to cause a denial of service (memory consumption and application crash) via HTML files with a… | EXPLOIT ✓HIGH 7.8EPSS 11.9% | 22 December 2005 |
| CVE-2005-4466 | Heap-based buffer overflow in the SIPParser function in i3sipmsg.dll in Interaction SIP Proxy before 3.0.011 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a REGISTER request with a SPI version number that… | EXPLOIT ✓HIGH 7.5EPSS 12.9% | 22 December 2005 |
| CVE-2005-4459 | Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1)… | HIGH 10.0EPSS 14.2% | 21 December 2005 |
| CVE-2005-4267 | Stack-based buffer overflow in Qualcomm WorldMail 3.0 allows remote attackers to execute arbitrary code via a long IMAP command that ends with a "}" character, as demonstrated using long (1) LIST, (2) LSUB, (3) SEARCH TEXT, (4) STATUS INBOX, (5)… | EXPLOIT ×2 ✓HIGH 7.5EPSS 66.8% | 21 December 2005 |
| CVE-2005-4411 | Buffer overflow in Mercury Mail Transport System 4.01b allows remote attackers to execute arbitrary code via a long request to TCP port 105. | EXPLOIT ×2 ✓HIGH 7.5EPSS 64.7% | 20 December 2005 |
| CVE-2005-4360 | The URL parser in Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2 allows remote attackers to execute arbitrary code via multiple requests to ".dll" followed by arguments such as "~0" through "~9", which causes ntdll.dll… | EXPLOIT ×2 ✓HIGH 7.8EPSS 86.7% | 20 December 2005 |
| CVE-2005-3652 | Heap-based buffer overflow in Citrix Program Neighborhood client 9.0 and earlier allows remote attackers to execute arbitrary code via a long name value in an Application Set response. | HIGH 7.5EPSS 16.0% | 16 December 2005 |
| CVE-2005-2831 | Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for… | HIGH 7.5EPSS 30.1% | 14 December 2005 |
| CVE-2005-2830 | Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability." | MEDIUM 5.0EPSS 35.5% | 14 December 2005 |
| CVE-2005-2829 | Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-assisted attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the… | MEDIUM 5.1EPSS 18.6% | 14 December 2005 |
| CVE-2005-3352 | Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps. | MEDIUM 4.3EPSS 73.7% | 13 December 2005 |
| CVE-2005-4197 | tunnelform.yaws in Nortel SSL VPN 4.2.1.6 allows remote attackers to execute arbitrary commands via a link in the a parameter, which is executed with extra privileges in a cryptographically signed Java Applet. | EXPLOIT ✓HIGH 7.5EPSS 11.9% | 13 December 2005 |
| CVE-2005-4145 | The MSDE version of Lyris ListManager 5.0 through 8.9b configures the sa account in the database to use a password with a small search space ("lyris" and up to 5 digits, possibly from the process ID), which allows remote attackers to gain access via a… | EXPLOIT ✓MEDIUM 6.5EPSS 43.9% | 10 December 2005 |
| CVE-2005-4134 | Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to cause a denial of service (CPU consumption and delayed application startup) via a web site with a large title, which is recorded in history.dat but not… | EXPLOIT ✓MEDIUM 5.0EPSS 12.6% | 9 December 2005 |
| CVE-2005-4131 | Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed range, which could lead to memory corruption… | EXPLOIT ✓MEDIUM 6.8EPSS 31.1% | 9 December 2005 |
| CVE-2005-4089 | Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files from other domains that are not valid Cascading Style Sheets (CSS) files,… | HIGH 7.1EPSS 22.1% | 8 December 2005 |
| CVE-2005-2923 | The IMAP server in IMail Server 8.20 in Ipswitch Collaboration Suite (ICS) before 2.02 allows remote attackers to cause a denial of service (crash) via a long argument to the LIST command, which causes IMail Server to reference invalid memory. | MEDIUM 4.0EPSS 10.8% | 7 December 2005 |
| CVE-2005-3945 | The SynAttackProtect protection in Microsoft Windows 2003 before SP1 and Windows 2000 before SP4 with Update Roll-up uses a hash of predictable data, which allows remote attackers to cause a denial of service (CPU consumption) via a flood of SYN packets… | HIGH 7.8EPSS 12.3% | 1 December 2005 |
| CVE-2005-3912 | Format string vulnerability in miniserv.pl Perl web server in Webmin before 1.250 and Usermin before 1.180, with syslog logging enabled, allows remote attackers to cause a denial of service (crash or memory consumption) and possibly execute arbitrary… | HIGH 7.5EPSS 14.5% | 30 November 2005 |
| CVE-2005-2124 | Unspecified vulnerability in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1, related to "An unchecked buffer" and possibly buffer overflows, allows remote attackers to execute arbitrary code via a… | EXPLOIT ×2 ✓HIGH 7.6EPSS 55.7% | 29 November 2005 |
| CVE-2005-2123 | Multiple integer overflows in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allow remote attackers to execute arbitrary code via crafted Windows Metafile (WMF) and Enhanced Metafile (EMF) format… | EXPLOIT ✓HIGH 7.5EPSS 61.5% | 29 November 2005 |
| CVE-2005-3862 | Buffer overflow in unalz before 0.53 allows remote attackers to execute arbitrary code via long file names in ALZ archives. | EXPLOIT ✓HIGH 7.5EPSS 20.4% | 29 November 2005 |
| CVE-2005-3792 | Multiple SQL injection vulnerabilities in the Search module in PHP-Nuke 7.8, and possibly other versions before 7.9 with patch 3.1, allows remote attackers to execute arbitrary SQL commands, as demonstrated via the query parameter in a stories type. | EXPLOIT ✓HIGH 7.5EPSS 44.3% | 24 November 2005 |
| CVE-2005-3774 | Cisco PIX 6.3 and 7.0 allows remote attackers to cause a denial of service (blocked new connections) via spoofed TCP packets that cause the PIX to create embryonic connections that that would not produce a valid connection with the end system, including… | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 18.2% | 23 November 2005 |
| CVE-2005-3758 | Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to inject arbitrary Javascript, and possibly other web script or HTML, via a proxystylesheet variable that contains a… | MEDIUM 4.3EPSS 19.1% | 22 November 2005 |
| CVE-2005-3757 | The Saxon XSLT parser in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to obtain sensitive information and execute arbitrary code via dangerous Java class methods in select attribute of xsl:value-of tags in… | EXPLOIT ×2 ✓HIGH 7.5EPSS 41.3% | 22 November 2005 |
| CVE-2005-3745 | Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates… | EXPLOIT ✓MEDIUM 4.3EPSS 25.7% | 22 November 2005 |
| CVE-2005-3737 | Buffer overflow in the SVG importer (style.cpp) of inkscape 0.41 through 0.42.2 might allow remote attackers to execute arbitrary code via a SVG file with long CSS style property values. | EXPLOIT ✓MEDIUM 5.1EPSS 13.4% | 22 November 2005 |
| CVE-2005-3694 | centericq 4.20.0-r3 with "Enable peer-to-peer communications" set allows remote attackers to cause a denial of service (segmentation fault and crash) via short zero-length packets, and possibly packets of length 1 or 2, as demonstrated using Nessus. | EXPLOIT ✓HIGH 7.8EPSS 12.0% | 20 November 2005 |
| CVE-2005-3684 | Multiple buffer overflows in freeFTPd 1.0.8, without logging enabled, allow remote authenticated attackers to cause a denial of service (application crash), and possibly execute arbitrary code, via long (1) MKD and (2) DELE commands. | EXPLOIT ✓HIGH 7.5EPSS 13.7% | 19 November 2005 |
| CVE-2005-3683 | Stack-based buffer overflow in freeFTPd before 1.0.9 with Logging enabled, allows remote attackers to cause a denial of service (application crash), and possibly execute arbitrary code, via a long USER command. | EXPLOIT ×2 ✓HIGH 7.5EPSS 71.5% | 19 November 2005 |
| CVE-2005-2629 | Integer overflow in RealNetworks RealPlayer 8, 10, and 10.5, RealOne Player 1 and 2, and Helix Player 10.0.0 allows remote attackers to execute arbitrary code via an .rm movie file with a large value in the length field of the first data packet, which… | EXPLOIT ✓MEDIUM 5.1EPSS 12.8% | 18 November 2005 |
| CVE-2005-3314 | Stack-based buffer overflow in the IMAP daemon in Novell Netmail 3.5.2 allows remote attackers to execute arbitrary code via "long verb arguments." | EXPLOIT ✓HIGH 7.5EPSS 65.7% | 18 November 2005 |
| CVE-2005-3116 | Stack-based buffer overflow in a shared library as used by the Volume Manager daemon (vmd) in VERITAS NetBackup Enterprise Server 5.0 MP1 to MP5 and 5.1 up to MP3A allows remote attackers to execute arbitrary code via a crafted packet. | EXPLOIT ✓HIGH 10.0EPSS 27.6% | 18 November 2005 |
| CVE-2005-3644 | PNP_GetDeviceList (upnp_getdevicelist) in UPnP for Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a DCE RPC request that specifies a large… | EXPLOIT ✓HIGH 7.8EPSS 42.3% | 17 November 2005 |
| CVE-2005-3634 | frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl… | EXPLOIT ✓MEDIUM 5.0EPSS 17.8% | 16 November 2005 |
| CVE-2005-3595 | By default Microsoft Windows XP Home Edition installs with a blank password for the Administrator account, which allows remote attackers to gain control of the computer. | HIGH 10.0EPSS 16.3% | 16 November 2005 |
| CVE-2005-3591 | Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via parameters to the… | EXPLOIT ✓HIGH 7.5EPSS 10.4% | 16 November 2005 |
| CVE-2005-3589 | Buffer overflow in FileZilla Server Terminal 0.9.4d may allow remote attackers to cause a denial of service (terminal crash) via a long USER ftp command. | EXPLOIT ✓HIGH 7.8EPSS 52.9% | 16 November 2005 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.