Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2005-3185

21
FAUCET Score

CVE-2005-3185 describes a stack-based buffer overflow in the ntlm_output function within http-ntlm.c, affecting wget 1.10, curl 7.13.2, libcurl 7.13.2, and other products utilizing libcurl when NTLM authentication is enabled. This vulnerability allows remote servers to execute arbitrary code by supplying a long NTLM username. With a CVSS score of 7.5, it is considered highly severe due to its network-based attack vector, low attack complexity, and potential for partial confidentiality, integrity, and availability impact. Despite its severity, there is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
7.13.2CPE matchmatch criteria
cpe:2.3:a:curl:curl:7.13.2:*:*:*:*:*:*:*
7.13.2CPE matchmatch criteria
cpe:2.3:a:libcurl:libcurl:7.13.2:*:*:*:*:*:*:*
1.10CPE matchmatch criteria
cpe:2.3:a:wget:wget:1.10:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.5HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
5.19%
Probability of exploitation in next 30 days
EPSS Percentile
91.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0519 is in the 85th percentile among its peer group of 51,485 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

jitsipatch availablevia llm_extracted
Fixed in: 7.14.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: curl-0:7.10.6-7.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: wget-0:1.10.2-0.30E
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: curl-0:7.12.1-6.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: wget-0:1.10.2-0.40E
View patch
sierra_wirelesspatch availablevia llm_extracted
Fixed in: 7.14.1
View patch

Vendor Advisories (3)

sierra_wirelessllm-sierra_wireless-00959cea5b90706bHIGH

NTLM Buffer Overflow

Oct 13, 2005
jitsillm-jitsi-c167cae1d001773aHIGH

NTLM Buffer Overflow

Oct 13, 2005
redhatCVE-2005-3185Important

security flaw

Oct 12, 2005

References

ftp.sco.com / pub/updates/OpenServer/SCOSA-2006.10/SCOSA-2006.10.txt
docs.info.apple.com / article.html
lists.trustix.org / pipermail/tsl-announce/2005-October/000354.html
secunia.com / advisories/17192
Vendor Advisory
secunia.com / advisories/17193
Vendor Advisory
secunia.com / advisories/17203
Vendor Advisory
secunia.com / advisories/17208
Vendor Advisory
secunia.com / advisories/17228
Vendor Advisory
secunia.com / advisories/17247
Vendor Advisory
secunia.com / advisories/17297
Vendor Advisory
secunia.com / advisories/17320
Vendor Advisory
secunia.com / advisories/17400
Vendor Advisory
secunia.com / advisories/17403
Vendor Advisory
secunia.com / advisories/17485
Vendor Advisory
secunia.com / advisories/17813
Vendor Advisory
secunia.com / advisories/17965
Vendor Advisory
secunia.com / advisories/19193
Vendor Advisory
securityreason.com / securityalert/82
securitytracker.com / id
securitytracker.com / id
exchange.xforce.ibmcloud.com / vulnerabilities/22721
slackware.com / security/viewer.php
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9810
usn.ubuntu.com / 205-1
debian.org / security/2005/dsa-919
gentoo.org / security/en/glsa/glsa-200510-19.xml
idefense.com / application/poi/display
PatchVendor Advisory
mandriva.com / security/advisories
novell.com / linux/security/advisories/2005_63_wget_curl.html
osvdb.org / 20011
redhat.com / archives/fedora-announce-list/2005-December/msg00020.html
redhat.com / archives/fedora-announce-list/2005-October/msg00055.html
redhat.com / support/errata/RHSA-2005-807.html
redhat.com / support/errata/RHSA-2005-812.html
securityfocus.com / bid/15102
securityfocus.com / bid/15647
vupen.com / english/advisories/2005/2088
Vendor Advisory
vupen.com / english/advisories/2005/2125
Vendor Advisory
vupen.com / english/advisories/2005/2659
Vendor Advisory