CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11669  CVE-2005-0463  Candidate  Unknown "major security flaws" in Ulog-php before 1.0, related to input validation, have unknown impact and attack vectors, probably related to SQL injection vulnerabilities in (1) host.php, (2) port.php, and (3) index.php.  Assigned (20050217)  None (candidate not yet proposed)    View
9917  CVE-2004-1489  Candidate  Opera 7.54 and earlier does not properly limit an applet"s access to internal Java packages from Sun, which allows remote attackers to gain sensitive information, such as user names and the installation directory.  Assigned (20050217)  None (candidate not yet proposed)    View
9918  CVE-2004-1490  Candidate  Opera 7.54 and earlier allows remote attackers to spoof file types in the download dialog via dots and non-breaking spaces (ASCII character code 160) in the (1) Content-Disposition or (2) Content-Type headers.  Assigned (20050217)  None (candidate not yet proposed)    View
9919  CVE-2004-1491  Candidate  Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code via a shortcut or launcher that contains an Exec entry.  Assigned (20050217)  None (candidate not yet proposed)    View
11670  CVE-2005-0464  Candidate  gr_osview in SGI IRIX 6.5.22, and possibly other 6.5 versions, does not drop privileges when opening description files while in debug mode, which allows local users to read a line from arbitrary files via the -d and -D options, which prints the line as a formatting error.  Assigned (20050218)  None (candidate not yet proposed)    View

Page 1175 of 20943, showing 5 records out of 104715 total, starting on record 5871, ending on 5875

Actions