CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12223  CVE-2005-1017  Candidate  SQL injection vulnerability in the Update_Events function in events_functions.asp in MaxWebPortal 1.33 and earlier allows remote attackers to execute arbitrary SQL commands via the EVENT_ID parameter, as demonstrated using events.asp.  Assigned (20050408)  None (candidate not yet proposed)    View
12224  CVE-2005-1018  Candidate  Buffer overflow in the UniversalAgent for Computer Associates (CA) BrightStor ARCserve Backup allows remote authenticated users to cause a denial of service or execute arbitrary code via an agent request to TCP port 6050 with a large argument before the option field.  Assigned (20050409)  None (candidate not yet proposed)    View
12225  CVE-2005-1019  Candidate  Buffer overflow in the getConfig function in Aeon 0.2a and earlier allows local users to gain privileges via a long HOME environment variable.  Assigned (20050410)  None (candidate not yet proposed)    View
12226  CVE-2005-1020  Candidate  Secure Shell (SSH) 2 in Cisco IOS 12.0 through 12.3 allows remote attackers to cause a denial of service (device reload) (1) via a username that contains a domain name when using a TACACS+ server to authenticate, (2) when a new SSH session is in the login phase and a currently logged in user issues a send command, or (3) when IOS is logging messages and an SSH session is terminated while the server is sending data.  Assigned (20050410)  None (candidate not yet proposed)    View
12227  CVE-2005-1021  Candidate  Memory leak in Secure Shell (SSH) in Cisco IOS 12.0 through 12.3, when authenticating against a TACACS+ server, allows remote attackers to cause a denial of service (memory consumption) via an incorrect username or password.  Assigned (20050410)  None (candidate not yet proposed)    View

Page 1369 of 20943, showing 5 records out of 104715 total, starting on record 6841, ending on 6845

Actions