CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6355 | CVE-2002-1973 | Candidate | Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Class (MFC) static libraries in Visual C++ 5.0, and 6.0 before SP3, as used in multiple products including BadBlue, allows remote attackers to cause a denial of service (access violation and crash) and possibly execute arbitrary code via a long query string that causes a parsing error. | Assigned (20050629) | None (candidate not yet proposed) | View | |
13267 | CVE-2005-2061 | Candidate | Infopop UBB.Threads before 6.5.2 Beta allows remote attackers to include arbitrary files via the language parameter in a cookie followed by a null (%00) byte. | Assigned (20050629) | None (candidate not yet proposed) | View | |
6356 | CVE-2002-1974 | Candidate | The FTP service in Zaurus PDAs SL-5000D and SL-5500 does not require authentication, which allows remote attackers to access the file system as root. | Assigned (20050629) | None (candidate not yet proposed) | View | |
13268 | CVE-2005-2062 | Candidate | Multiple SQL injection vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to execute arbitrary SQL commands via the catid parameter to (1) default.asp or (2) buyersend.asp, (3) Administrator ID field in admin.asp, E-mail field in (4) advertiserstart.asp or (5) buyer.asp, or Keyword field in search.asp. | Assigned (20050629) | None (candidate not yet proposed) | View | |
6357 | CVE-2002-1975 | Candidate | Sharp Zaurus PDA SL-5000D and SL-5500 uses a salt of "A0" to encrypt the screen-locking password as stored in the Security.conf file, which makes it easier for local users to guess the password via brute force methods. | Assigned (20050629) | None (candidate not yet proposed) | View |
Page 1749 of 20943, showing 5 records out of 104715 total, starting on record 8741, ending on 8745