CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12955  CVE-2005-1749  Candidate  Buffer overflow in BEA WebLogic Server and WebLogic Express 6.1 Service Pack 4 allows remote attackers to cause a denial of service (CPU consumption from thread looping).  Assigned (20050525)  None (candidate not yet proposed)    View
12956  CVE-2005-1750  Candidate  SQL injection vulnerability in login.asp in ezdwc NewsletterEz 3.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.  Assigned (20050525)  None (candidate not yet proposed)    View
12957  CVE-2005-1751  Candidate  Race condition in shtool 2.0.1 and earlier allows local users to create or modify arbitrary files via a symlink attack on the .shtool.$$ temporary file, a different vulnerability than CVE-2005-1759.  Assigned (20050525)  None (candidate not yet proposed)    View
12958  CVE-2005-1752  Candidate  viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file_name parameter.  Assigned (20050526)  None (candidate not yet proposed)    View
12959  CVE-2005-1753  Candidate  ** DISPUTED ** ReadMessage.jsp in JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to view other users" e-mail attachments via a direct request to /mailboxesdir/username@domainname. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products."  Assigned (20050526)  None (candidate not yet proposed)    View

Page 1610 of 20943, showing 5 records out of 104715 total, starting on record 8046, ending on 8050

Actions