CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12828  CVE-2005-1622  Candidate  Cross-site scripting (XSS) vulnerability in productsByCategory.asp in MetaCart e-Shop allows remote attackers to inject arbitrary web script or HTML via the strCatalog_NAME parameter.  Assigned (20050516)  None (candidate not yet proposed)    View
12795  CVE-2005-1589  Candidate  The pkt_ioctl function in the pktcdvd block device ioctl handler (pktcdvd.c) in Linux kernel 2.6.12-rc4 and earlier calls the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space and allows local users to cause a denial of service and possibly execute arbitrary code, a similar vulnerability to CVE-2005-1264.  Assigned (20050516)  None (candidate not yet proposed)    View
12796  CVE-2005-1590  Candidate  The Altiris Client Service for Windows (ACLIENT.EXE) 6.0.88 allows local users to disable password protection and access the administrative interface by finding and showing the "Altiris Client Service" hidden window, disabling the password protection, disabling the "Hide client tray icon box" option, then opening the AClient tray icon and using the View Log File option, a different vulnerability than CVE-2004-2070.  Assigned (20050516)  None (candidate not yet proposed)    View
12797  CVE-2005-1591  Candidate  Unknown vulnerability in NIS+ on Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (rpc.nisd disabled and NIS+ unavailable) via unknown vectors.  Assigned (20050516)  None (candidate not yet proposed)    View
12798  CVE-2005-1592  Candidate  Multiple "javascript vulerabilities in BB code" in BirdBlog before 1.3.1 allow remote attackers to inject arbitrary Javascript.  Assigned (20050516)  None (candidate not yet proposed)    View

Page 1576 of 20943, showing 5 records out of 104715 total, starting on record 7876, ending on 7880

Actions