CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12609  CVE-2005-1403  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in JustWilliam"s Amazon Webstore 04050100 allow remote attackers to inject arbitrary web script or HTML via the (1) image parameter to closeup.php, the (2) currentIsExpanded or (3) searchFor parameters to index.php, (4) the currentNumber parameter to software_CAD_Technical_60002_uk.htm, or (5) a cookie.  Assigned (20050503)  None (candidate not yet proposed)    View
12610  CVE-2005-1404  Candidate  MyPHP Forum 1.0 allows remote attackers to spoof the username by modifying the (1) nbuser parameter to post.php or (2) sender parameter to privmsg.php.  Assigned (20050503)  None (candidate not yet proposed)    View
12611  CVE-2005-1405  Candidate  HTTP response splitting vulnerability in the @SetHTTPHeader function in Lotus Domino 6.5.x before 6.5.4 and 6.0.x before 6.0.5 allows attackers to poison the web cache via malicious applications.  Assigned (20050503)  None (candidate not yet proposed)    View
12612  CVE-2005-1406  Candidate  The kernel in FreeBSD 4.x to 4.11 and 5.x to 5.4 does not properly clear certain fixed-length buffers when copying variable-length data for use by applications, which could allow those applications to read previously used sensitive memory.  Assigned (20050503)  None (candidate not yet proposed)    View
12613  CVE-2005-1407  Candidate  Skype for Windows 1.2.0.0 to 1.2.0.46 allows local users to bypass the identity check for an authorized application, then call arbitrary Skype API functions by modifying or replacing that application.  Assigned (20050503)  None (candidate not yet proposed)    View

Page 1460 of 20943, showing 5 records out of 104715 total, starting on record 7296, ending on 7300

Actions