CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13355  CVE-2005-2149  Candidate  config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.  Assigned (20050706)  None (candidate not yet proposed)    View
13356  CVE-2005-2150  Candidate  Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which allows remote attackers to (1) list Windows services via svcctl or (2) read eventlogs via eventlog.  Assigned (20050706)  None (candidate not yet proposed)    View
13357  CVE-2005-2151  Candidate  spf.c in Courier Mail Server does not properly handle DNS failures when looking up Sender Policy Framework (SPF) records, which could allow attackers to cause memory corruption.  Assigned (20050706)  None (candidate not yet proposed)    View
13358  CVE-2005-2152  Candidate  SQL injection vulnerability in Geeklog before 1.3.11 allows remote attackers to execute arbitrary SQL commands via user comments for an article.  Assigned (20050706)  None (candidate not yet proposed)    View
13359  CVE-2005-2153  Candidate  SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands via the ticket variable.  Assigned (20050706)  None (candidate not yet proposed)    View

Page 1773 of 20943, showing 5 records out of 104715 total, starting on record 8861, ending on 8865

Actions