CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12853  CVE-2005-1647  Candidate  Gurgens (GASoft) Guest Book 2.1 stores the db/Genid.dat database file under the web document root with insufficient access control, which allows remote attackers to obtain and decrypt usernames and passwords.  Assigned (20050518)  None (candidate not yet proposed)    View
12854  CVE-2005-1648  Candidate  Gurgens (GASoft) Ultimate Forum 1.0 stores the db/Genid.dat database file under the web document root with insufficient access control, which allows remote attackers to obtain and decrypt usernames and passwords.  Assigned (20050518)  None (candidate not yet proposed)    View
12855  CVE-2005-1649  Candidate  The IPv6 support in Windows XP SP2, 2003 Server SP1, and Longhorn, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, a variant of CVE-2005-0688 and a reoccurrence of the "Land" vulnerability (CVE-1999-0016).  Assigned (20050518)  None (candidate not yet proposed)    View
12856  CVE-2005-1650  Candidate  The web mail service in Woppoware PostMaster 4.2.2 (build 3.2.5) generates different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames.  Assigned (20050518)  None (candidate not yet proposed)    View
12857  CVE-2005-1651  Candidate  Directory traversal vulnerability in message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in the wmm parameter.  Assigned (20050518)  None (candidate not yet proposed)    View

Page 1582 of 20943, showing 5 records out of 104715 total, starting on record 7906, ending on 7910

Actions