CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11810 | CVE-2005-0604 | Candidate | lnss.exe in GFI Languard Network Security Scanner 5.0 stores the username and password in memory in plaintext, which could allow local administrators to obtain domain administrator credentials. | Assigned (20050301) | None (candidate not yet proposed) | View | |
11811 | CVE-2005-0605 | Candidate | scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value that leads to a buffer overflow. | Assigned (20050301) | None (candidate not yet proposed) | View | |
11812 | CVE-2005-0606 | Candidate | Cross-site scripting (XSS) vulnerability in settings.inc.php for CubeCart 2.0.0 through 2.0.5, as used in multiple PHP files, allows remote attackers to inject arbitrary HTML or web script via the (1) cat_id, (2) PHPSESSID, (3) view_doc, (4) product, (5) session, (6) catname, (7) search, or (8) page parameters. | Assigned (20050301) | None (candidate not yet proposed) | View | |
11813 | CVE-2005-0607 | Candidate | CubeCart 2.0.0 through 2.0.5 allows remote attackers to determine the full path of the server via direct calls without parameters to (1) information.php, (2) language.php, (3) list_docs.php, (4) popular_prod.php, (5) sale.php, (6) subfooter.inc.php, (7) subheader.inc.php, (8) cat_navi.php, or (9) check_sum.php, which reveals the path in a PHP error message. | Assigned (20050301) | None (candidate not yet proposed) | View | |
11814 | CVE-2005-0608 | Candidate | Heap-based buffer overflow in server.cpp for WebMod 0.47 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a POST request with a Content-Length that is less than the amount of data that is actually sent. | Assigned (20050301) | None (candidate not yet proposed) | View |
Page 1257 of 20943, showing 5 records out of 104715 total, starting on record 6281, ending on 6285