CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12699  CVE-2005-1493  Candidate  Directory traversal vulnerability in SimpleCam 1.2 allows remote attackers to read arbitrary files via a .. (dot dot backslash) in the URL.  Assigned (20050511)  None (candidate not yet proposed)    View
12700  CVE-2005-1494  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in admin.cgi in MegaBook 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) entryid or (2) password parameter.  Assigned (20050511)  None (candidate not yet proposed)    View
12701  CVE-2005-1495  Candidate  Oracle Database 9i and 10g disables Fine Grained Audit (FGA) after the SYS user executes a SELECT statement on an FGA object, which makes it easier for attackers to escape detection.  Assigned (20050511)  None (candidate not yet proposed)    View
12702  CVE-2005-1496  Candidate  The DBMS_Scheduler in Oracle 10g allows remote attackers with CREATE JOB privileges to gain additional privileges by changing SESSION_USER to the SYS user.  Assigned (20050511)  None (candidate not yet proposed)    View
12703  CVE-2005-1497  Candidate  index.php in myBloggie 2.1.1 allows remote attackers to obtain sensitive information via an invalid post_id parameter, which reveals the path in an error message.  Assigned (20050511)  None (candidate not yet proposed)    View

Page 1551 of 20943, showing 5 records out of 104715 total, starting on record 7751, ending on 7755

Actions