CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12147 | CVE-2005-0941 | Candidate | The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but process memory using 32 bit values, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a DOC document with certain length values, which leads to a heap-based buffer overflow. | Assigned (20050331) | None (candidate not yet proposed) | View | |
12149 | CVE-2005-0943 | Candidate | Cisco VPN 3000 series Concentrator running firmware 4.1.7.A and earlier allows remote attackers to cause a denial of service (device reload or drop user connection) via a crafted HTTPS packet. | Assigned (20050403) | None (candidate not yet proposed) | View | |
12150 | CVE-2005-0944 | Candidate | Unknown vulnerability in Microsoft Jet DB engine (msjet40.dll) 4.00.8618.0, related to insufficient data validation, allows remote attackers to execute arbitrary code via a crafted mdb file. | Assigned (20050403) | None (candidate not yet proposed) | View | |
12151 | CVE-2005-0945 | Candidate | Cross-site scripting (XSS) vulnerability in ACS Blog 1.1.1 allows remote attackers to inject arbitrary web script or HTML via onmouseover or onload events in (1) img, (2) link, or (3) mail tags. | Assigned (20050403) | None (candidate not yet proposed) | View | |
12152 | CVE-2005-0946 | Candidate | SQL injection vulnerability in phpCoin 1.2.1b and earlier allows remote attackers to execute arbitrary SQL commands via the (1) term/keywords field on the search page, (2) username or (3) e-mail field on the forgot password page, or (4) domain name on the ordering new package page. | Assigned (20050403) | None (candidate not yet proposed) | View |
Page 1354 of 20943, showing 5 records out of 104715 total, starting on record 6766, ending on 6770