CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12072  CVE-2005-0866  Candidate  cdrecord before 4:2.0, when DEBUG is enabled, allows local users to overwrite arbitrary files via a symlink attack on temporary files.  Assigned (20050326)  None (candidate not yet proposed)    View
12073  CVE-2005-0867  Candidate  Integer overflow in Linux kernel 2.6 allows local users to overwrite kernel memory by writing to a sysfs file.  Assigned (20050326)  None (candidate not yet proposed)    View
12074  CVE-2005-0868  Candidate  AS/400 Telnet 5250 terminal emulation clients, as implemented by (1) IBM client access, (2) Bosanova, (3) PowerTerm, (4) Mochasoft, and possibly other emulations, allows malicious AS/400 servers to execute arbitrary commands via a STRPCO (Start PC Organizer) command followed by STRPCCMD (Start PC command), as demonstrated by creating a backdoor account using REXEC.  Assigned (20050326)  None (candidate not yet proposed)    View
12075  CVE-2005-0869  Candidate  phpSysInfo 2.3 allows remote attackers to obtain sensitive information via a direct request to (1) class.OpenBSD.inc.php, (2) class.NetBSD.inc.php, (3) class.FreeBSD.inc.php, (4) class.Darwin.inc.php, (5) XPath.class.php, (6) system_header.php, or (7) system_footer.php, which reveal the path in a PHP error message.  Assigned (20050326)  None (candidate not yet proposed)    View
12076  CVE-2005-0870  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in phpSysInfo 2.3, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) sensor_program parameter to index.php, (2) text[language], (3) text[template], or (4) hide_picklist parameter to system_footer.php.  Assigned (20050326)  None (candidate not yet proposed)    View

Page 1331 of 20943, showing 5 records out of 104715 total, starting on record 6651, ending on 6655

Actions