CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11396  CVE-2005-0190  Candidate  Directory traversal vulnerability in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to delete arbitrary files via a Real Metadata Packages (RMP) file with a FILENAME tag containing .. (dot dot) sequences in a filename that ends with a ? (question mark) and an allowed file extension (e.g. .mp3), which bypasses the check for the file extension.  Assigned (20050128)  None (candidate not yet proposed)    View
11397  CVE-2005-0191  Candidate  Off-by-one buffer overflow in the processing of tags in Real Metadata Package (RMP) files in RealPlayer 10.5 (6.0.12.1040) and earlier could allow remote attackers to execute arbitrary code via a long tag.  Assigned (20050128)  None (candidate not yet proposed)    View
11398  CVE-2005-0192  Candidate  Directory traversal vulnerability in the parsing of Skin file names in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in an RJS filename.  Assigned (20050128)  None (candidate not yet proposed)    View
11399  CVE-2005-0193  Candidate  Buffer overflow in the (1) -v and (2) -a switches in mRouter in iSync 1.5 in Mac OS X 10.3.7 and earlier allows local users to execute arbitrary code.  Assigned (20050128)  None (candidate not yet proposed)    View
9816  CVE-2004-1388  Candidate  Format string vulnerability in the gpsd_report function for BerliOS GPD daemon (gpsd, formerly pygps) 1.9.0 through 2.7 allows remote attackers to execute arbitrary code via certain GPS requests containing format string specifiers that are not properly handled in syslog calls.  Assigned (20050131)  None (candidate not yet proposed)    View

Page 1092 of 20943, showing 5 records out of 104715 total, starting on record 5456, ending on 5460

Actions