CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13141  CVE-2005-1935  Candidate  Heap-based buffer overflow in the BERDecBitString function in Microsoft ASN.1 library (MSASN1.DLL) allows remote attackers to execute arbitrary code via nested constructed bit strings, which leads to a realloc of a non-null pointer and causes the function to overwrite previously freed memory, as demonstrated using a SPNEGO token with a constructed bit string during HTTP authentication, and a different vulnerability than CVE-2003-0818. NOTE: the researcher has claimed that MS:MS04-007 fixes this issue.  Assigned (20050609)  None (candidate not yet proposed)    View
13142  CVE-2005-1936  Candidate  Unknown vulnerability in the web server for the ESS/ Network Controller for Xerox Document Centre 240 through 555 running System Software 27.18.017 and earlier allows attackers to "gain unauthorized access."  Assigned (20050612)  None (candidate not yet proposed)    View
13143  CVE-2005-1937  Candidate  A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2004-0718.  Assigned (20050613)  None (candidate not yet proposed)    View
13144  CVE-2005-1938  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-1250. Reason: This candidate is a duplicate of CVE-2005-1250. Notes: this duplicate occurred as a result of multiple independent discoveries and insufficient coordination by the vendor and CNA. All CVE users should reference CVE-2005-1250 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20050613)  None (candidate not yet proposed)    View
13145  CVE-2005-1939  Candidate  Directory traversal vulnerability in Ipswitch WhatsUp Small Business 2004 allows remote attackers to read arbitrary files via ".." (dot dot) sequences in a request to the Report service (TCP 8022).  Assigned (20050613)  None (candidate not yet proposed)    View

Page 1657 of 20943, showing 5 records out of 104715 total, starting on record 8281, ending on 8285

Actions