CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11573 | CVE-2005-0367 | Candidate | Multiple directory traversal vulnerabilities in ArGoSoft Mail Server 1.8.7.3 allow remote authenticated users to read, delete, or upload arbitrary files via a .. (dot dot) in (1) the filename of an e-mail attachment, (2) the _msgatt.rec file, (3) and the /msg, /delete, /folderadd, and /folderdelete operations for the Folder parameter. | Assigned (20050211) | None (candidate not yet proposed) | View | |
11574 | CVE-2005-0368 | Candidate | Multiple SQL injection vulnerabilities in CMScore allow remote attackers to execute arbitrary SQL commands via the (1) EntryID or (2) searchterm parameter to index.php, or (3) username parameter to authenticate.php. | Assigned (20050211) | None (candidate not yet proposed) | View | |
11575 | CVE-2005-0369 | Candidate | Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a packet with a large (1) descriptor ID or (2) claim_id, which exceeds the boundaries of an array. | Assigned (20050211) | None (candidate not yet proposed) | View | |
11576 | CVE-2005-0370 | Candidate | Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (network disconnection) via an empty UDP packet, which is not properly distinguished from the "no new packets" state of the associated socket. | Assigned (20050211) | None (candidate not yet proposed) | View | |
11577 | CVE-2005-0371 | Candidate | Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (freeze) via a large number of player connections that do not send any data. | Assigned (20050211) | None (candidate not yet proposed) | View |
Page 1136 of 20943, showing 5 records out of 104715 total, starting on record 5676, ending on 5680