CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12955 | CVE-2005-1749 | Candidate | Buffer overflow in BEA WebLogic Server and WebLogic Express 6.1 Service Pack 4 allows remote attackers to cause a denial of service (CPU consumption from thread looping). | Assigned (20050525) | None (candidate not yet proposed) | View | |
12956 | CVE-2005-1750 | Candidate | SQL injection vulnerability in login.asp in ezdwc NewsletterEz 3.0 allows remote attackers to execute arbitrary SQL commands via the password parameter. | Assigned (20050525) | None (candidate not yet proposed) | View | |
12957 | CVE-2005-1751 | Candidate | Race condition in shtool 2.0.1 and earlier allows local users to create or modify arbitrary files via a symlink attack on the .shtool.$$ temporary file, a different vulnerability than CVE-2005-1759. | Assigned (20050525) | None (candidate not yet proposed) | View | |
12958 | CVE-2005-1752 | Candidate | viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file_name parameter. | Assigned (20050526) | None (candidate not yet proposed) | View | |
12959 | CVE-2005-1753 | Candidate | ** DISPUTED ** ReadMessage.jsp in JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to view other users" e-mail attachments via a direct request to /mailboxesdir/username@domainname. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products." | Assigned (20050526) | None (candidate not yet proposed) | View |
Page 1610 of 20943, showing 5 records out of 104715 total, starting on record 8046, ending on 8050