CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12029 | CVE-2005-0823 | Candidate | ThePoolClub (1) iPool and (2) iSnooker 1.6.81 and earlier stores usernames and passwords in cleartext in the MyDetails.txt file, which allows local users to gain privileges. | Assigned (20050320) | None (candidate not yet proposed) | View | |
12032 | CVE-2005-0826 | Candidate | OllyDbg 1.10 and earlier allows remote attackers to cause a denial of service (application crash) via a dynamic link library (DLL) with a long filename. | Assigned (20050322) | None (candidate not yet proposed) | View | |
12033 | CVE-2005-0827 | Candidate | Viewcat.php in (1) RUNCMS 1.1A, (2) Ciamos 0.9.2 RC1, e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allow remote attackers to obtain sensitive information via an invalid parameter to the convertorderbytrans function, which reveals the path in a PHP error message. | Assigned (20050322) | None (candidate not yet proposed) | View | |
12034 | CVE-2005-0828 | Candidate | highlight.php in (1) RUNCMS 1.1A, (2) CIAMOS 0.9.2 RC1, (3) e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allows remote attackers to read arbitrary PHP files by specifying the pathname in the file parameter, as demonstrated by reading database configuration information from mainfile.php. | Assigned (20050322) | None (candidate not yet proposed) | View | |
12035 | CVE-2005-0829 | Candidate | Cross-site scripting (XSS) vulnerability in setuser.php of the Digitanium addon to PHP-Fusion 5.01 allows remote attackers to inject arbitrary web script or HTML via the (1) user_name or (2) user_pass parameters. | Assigned (20050322) | None (candidate not yet proposed) | View |
Page 1317 of 20943, showing 5 records out of 104715 total, starting on record 6581, ending on 6585