CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12450  CVE-2005-1244  Candidate  ** DISPUTED ** Directory traversal vulnerability in the third party tool from NetIQ, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request. NOTE: the vendor has disputed this issue, saying that "neither NetIQ Security Manager nor our iSeries Security Solutions are vulnerable."  Assigned (20050424)  None (candidate not yet proposed)    View
12451  CVE-2005-1245  Candidate  Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.2, when using HTML Tidy ($wgUseTidy), allows remote attackers to inject arbitrary web script or HTML via unknown vectors.  Assigned (20050424)  None (candidate not yet proposed)    View
12452  CVE-2005-1246  Candidate  Format string vulnerability in the snmppd_log function in snmppd_util.c for snmppd 0.4.5 and earlier may allow remote attackers to cause a denial of service or execute arbitrary code via format string specifiers that are not properly handled in a syslog call.  Assigned (20050425)  None (candidate not yet proposed)    View
12453  CVE-2005-1247  Candidate  webadmin.exe in Novell Nsure Audit 1.0.1 allows remote attackers to cause a denial of service via malformed ASN.1 packets in corrupt client certificates to an SSL server, as demonstrated using an exploit for the OpenSSL ASN.1 parsing vulnerability.  Assigned (20050425)  None (candidate not yet proposed)    View
12454  CVE-2005-1248  Candidate  Buffer overflow in Apple iTunes before 4.8 allows remote attackers to execute arbitrary code via a crafted MPEG4 file.  Assigned (20050425)  None (candidate not yet proposed)    View

Page 1428 of 20943, showing 5 records out of 104715 total, starting on record 7136, ending on 7140

Actions