CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11404  CVE-2005-0198  Candidate  A logic error in the CRAM-MD5 code for the University of Washington IMAP (UW-IMAP) server, when Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5) is enabled, does not properly enforce all the required conditions for successful authentication, which allows remote attackers to authenticate as arbitrary users.  Assigned (20050131)  None (candidate not yet proposed)    View
11405  CVE-2005-0199  Candidate  Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long MODE line that causes an incorrect length calculation, which leads to a buffer overflow.  Assigned (20050131)  None (candidate not yet proposed)    View
11406  CVE-2005-0200  Candidate  TikiWiki before 1.8.5 does not properly validate files that have been uploaded to the temp directory, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2004-1386.  Assigned (20050131)  None (candidate not yet proposed)    View
11407  CVE-2005-0201  Candidate  D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another user"s per-user session bus via that socket.  Assigned (20050201)  None (candidate not yet proposed)    View
11408  CVE-2005-0202  Candidate  Directory traversal vulnerability in the true_path function in private.py for Mailman 2.1.5 and earlier allows remote attackers to read arbitrary files via ".../....///" sequences, which are not properly cleansed by regular expressions that are intended to remove "../" and "./" sequences.  Assigned (20050201)  None (candidate not yet proposed)    View

Page 1094 of 20943, showing 5 records out of 104715 total, starting on record 5466, ending on 5470

Actions