CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12311  CVE-2005-1105  Candidate  Directory traversal vulnerability in the MimeBodyPart.getFileName method in JavaMail 1.3.2 allows remote attackers to write arbitrary files via a .. (dot dot) in the filename in the Content-Disposition header.  Assigned (20050413)  None (candidate not yet proposed)    View
77847  CVE-2015-0584  Candidate  The image-upgrade implementation on Cisco Desktop Collaboration Experience (aka Collaboration Desk Experience or DX) DX650 endpoints allows local users to execute arbitrary OS commands via an unspecified parameter, aka Bug ID CSCus38947.  Assigned (20150107)  None (candidate not yet proposed)    View
12567  CVE-2005-1361  Candidate  Multiple SQL injection vulnerabilities in MetaCart e-Shop 8.0 allow remote attackers to execute arbitrary SQL commands via the (1) intProdID parameter in product.asp or (2) strCatalog_NAME parameter to productsByCategory.asp.  Assigned (20050428)  None (candidate not yet proposed)    View
78103  CVE-2015-0840  Candidate  The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian source control file (.dsc).  Assigned (20150107)  None (candidate not yet proposed)    View
12823  CVE-2005-1617  Candidate  Willings WebCam and WebCam Lite 2.8 and earlier stores the password in memory in plaintext, which allows local users to gain sensitive information.  Assigned (20050516)  None (candidate not yet proposed)    View

Page 1823 of 20943, showing 5 records out of 104715 total, starting on record 9111, ending on 9115

Actions