CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11246  CVE-2005-0040  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in DotNetNuke before 3.0.12 allow remote attackers to inject arbitrary web script or HTML via the (1) register a new user page, (2) User-Agent, or (3) Username, which is not properly quoted before sending to the error log.  Assigned (20050107)  None (candidate not yet proposed)    View
11247  CVE-2005-0041  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20050107)  None (candidate not yet proposed)    View
11248  CVE-2005-0042  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20050107)  None (candidate not yet proposed)    View
9804  CVE-2004-1376  Candidate  Directory traversal vulnerability in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote malicious FTP servers to overwrite arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.  Assigned (20050110)  None (candidate not yet proposed)    View
11249  CVE-2005-0043  Candidate  Buffer overflow in Apple iTunes 4.7 allows remote attackers to execute arbitrary code via a long URL in (1) .m3u or (2) .pls playlist files.  Assigned (20050110)  None (candidate not yet proposed)    View

Page 1059 of 20943, showing 5 records out of 104715 total, starting on record 5291, ending on 5295

Actions