CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13123  CVE-2005-1917  Candidate  kpopper 1.0 and earlier allows local users to create and overwrite arbitrary files via a symlink attack on the .popper-new temporary file.  Assigned (20050608)  None (candidate not yet proposed)    View
13124  CVE-2005-1918  Candidate  The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an "incorrect optimization" that allows user-assisted attackers to overwrite arbitrary files via a crafted tar file, probably involving "/../" sequences with a leading "/".  Assigned (20050608)  None (candidate not yet proposed)    View
13125  CVE-2005-1919  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.  Assigned (20050608)  None (candidate not yet proposed)    View
13126  CVE-2005-1920  Candidate  The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information.  Assigned (20050608)  None (candidate not yet proposed)    View
13127  CVE-2005-1921  Candidate  Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.  Assigned (20050608)  None (candidate not yet proposed)    View

Page 1653 of 20943, showing 5 records out of 104715 total, starting on record 8261, ending on 8265

Actions