CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12885  CVE-2005-1679  Candidate  Stack-based buffer overflow in the error directive in picasm 1.12b and earlier allows attackers to execute arbitrary code via a long error message.  Assigned (20050520)  None (candidate not yet proposed)    View
12886  CVE-2005-1680  Candidate  D-Link DSL-502T, DSL-504T, DSL-562T, and DSL-G604T, when /cgi-bin/firmwarecfg is executed, allows remote attackers to bypass authentication (1) if their IP address already exists in /var/tmp/fw_ip or (2) if their request is the first, which causes /var/tmp/fw_ip to be created and contain their IP address.  Assigned (20050520)  None (candidate not yet proposed)    View
12887  CVE-2005-1681  Candidate  PHP remote file inclusion vulnerability in common.php in phpATM 1.21, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the include_location parameter to index.php.  Assigned (20050520)  None (candidate not yet proposed)    View
12888  CVE-2005-1682  Candidate  ** DISPUTED ** JavaMail API, as used by Solstice Internet Mail Server POP3 2.0, does not properly validate the message number in the MimeMessage constructor in javax.mail.internet.InternetHeaders, which allows remote authenticated users to read other users" e-mail messages by modifying the msgno parameter. NOTE: Sun disputes this issue, stating "The report makes references to source code and files that do not exist in the mentioned products."  Assigned (20050520)  None (candidate not yet proposed)    View
12889  CVE-2005-1683  Candidate  Buffer overflow in winword.exe 10.2627.6714 and earlier in Microsoft Word for the Macintosh, before SP3 for Word 2002, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted mcw file.  Assigned (20050520)  None (candidate not yet proposed)    View

Page 1596 of 20943, showing 5 records out of 104715 total, starting on record 7976, ending on 7980

Actions