CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11396 | CVE-2005-0190 | Candidate | Directory traversal vulnerability in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to delete arbitrary files via a Real Metadata Packages (RMP) file with a FILENAME tag containing .. (dot dot) sequences in a filename that ends with a ? (question mark) and an allowed file extension (e.g. .mp3), which bypasses the check for the file extension. | Assigned (20050128) | None (candidate not yet proposed) | View | |
11397 | CVE-2005-0191 | Candidate | Off-by-one buffer overflow in the processing of tags in Real Metadata Package (RMP) files in RealPlayer 10.5 (6.0.12.1040) and earlier could allow remote attackers to execute arbitrary code via a long tag. | Assigned (20050128) | None (candidate not yet proposed) | View | |
11398 | CVE-2005-0192 | Candidate | Directory traversal vulnerability in the parsing of Skin file names in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in an RJS filename. | Assigned (20050128) | None (candidate not yet proposed) | View | |
11399 | CVE-2005-0193 | Candidate | Buffer overflow in the (1) -v and (2) -a switches in mRouter in iSync 1.5 in Mac OS X 10.3.7 and earlier allows local users to execute arbitrary code. | Assigned (20050128) | None (candidate not yet proposed) | View | |
9816 | CVE-2004-1388 | Candidate | Format string vulnerability in the gpsd_report function for BerliOS GPD daemon (gpsd, formerly pygps) 1.9.0 through 2.7 allows remote attackers to execute arbitrary code via certain GPS requests containing format string specifiers that are not properly handled in syslog calls. | Assigned (20050131) | None (candidate not yet proposed) | View |
Page 1092 of 20943, showing 5 records out of 104715 total, starting on record 5456, ending on 5460