CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12769 | CVE-2005-1563 | Candidate | Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 displays a different error message depending on whether a product exists or not, which allows remote attackers to determine hidden products. | Assigned (20050514) | None (candidate not yet proposed) | View | |
12770 | CVE-2005-1564 | Candidate | post_bug.cgi in Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 allows remote authenticated users to "enter bugs into products that are closed for bug entry" by modifying the URL to specify the name of the product. | Assigned (20050514) | None (candidate not yet proposed) | View | |
12771 | CVE-2005-1565 | Candidate | Bugzilla 2.17.1 through 2.18, 2.19.1, and 2.19.2, when a user is prompted to log in while attempting to view a chart, displays the password in the URL, which may allow local users to gain sensitive information from web logs or browser history. | Assigned (20050514) | None (candidate not yet proposed) | View | |
12772 | CVE-2005-1566 | Candidate | Acrowave AAP-3100AR wireless router allows remote attackers to bypass authentication by pressing CTRL-C at the username or password prompt in a telnet session, which causes the shell to crash and restart, then leave the user in the new shell. | Assigned (20050514) | None (candidate not yet proposed) | View | |
12773 | CVE-2005-1567 | Candidate | SQL injection vulnerability in topic.php in DirectTopics 2.1 and 2.2 allows remote attackers to execute arbitrary SQL commands via the topic parameter. | Assigned (20050514) | None (candidate not yet proposed) | View |
Page 1565 of 20943, showing 5 records out of 104715 total, starting on record 7821, ending on 7825