CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11810  CVE-2005-0604  Candidate  lnss.exe in GFI Languard Network Security Scanner 5.0 stores the username and password in memory in plaintext, which could allow local administrators to obtain domain administrator credentials.  Assigned (20050301)  None (candidate not yet proposed)    View
11811  CVE-2005-0605  Candidate  scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value that leads to a buffer overflow.  Assigned (20050301)  None (candidate not yet proposed)    View
11812  CVE-2005-0606  Candidate  Cross-site scripting (XSS) vulnerability in settings.inc.php for CubeCart 2.0.0 through 2.0.5, as used in multiple PHP files, allows remote attackers to inject arbitrary HTML or web script via the (1) cat_id, (2) PHPSESSID, (3) view_doc, (4) product, (5) session, (6) catname, (7) search, or (8) page parameters.  Assigned (20050301)  None (candidate not yet proposed)    View
11813  CVE-2005-0607  Candidate  CubeCart 2.0.0 through 2.0.5 allows remote attackers to determine the full path of the server via direct calls without parameters to (1) information.php, (2) language.php, (3) list_docs.php, (4) popular_prod.php, (5) sale.php, (6) subfooter.inc.php, (7) subheader.inc.php, (8) cat_navi.php, or (9) check_sum.php, which reveals the path in a PHP error message.  Assigned (20050301)  None (candidate not yet proposed)    View
11814  CVE-2005-0608  Candidate  Heap-based buffer overflow in server.cpp for WebMod 0.47 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a POST request with a Content-Length that is less than the amount of data that is actually sent.  Assigned (20050301)  None (candidate not yet proposed)    View

Page 1257 of 20943, showing 5 records out of 104715 total, starting on record 6281, ending on 6285

Actions