CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11690  CVE-2005-0484  Candidate  Format string vulnerability in gprostats for GProFTPD before 8.1.9 may allow remote attackers to execute arbitrary code via an FTP transfer with a crafted filename that causes format string specifiers to be inserted into the ProFTPD transfer log.  Assigned (20050219)  None (candidate not yet proposed)    View
11689  CVE-2005-0483  Candidate  Multiple directory traversal vulnerabilities in sitenfo.sh, sitezipchk.sh, and siteziplist.sh in Glftpd 1.26 to 2.00 allow remote authenticated users to (1) determine the existence of arbitrary files, (2) list files in restricted directories, or (3) read arbitrary files from within ZIP or gzip files, via .. (dot dot) sequences and globbing ("*") characters in a SITE NFO command.  Assigned (20050219)  None (candidate not yet proposed)    View
11688  CVE-2005-0482  Candidate  TrackerCam 5.12 and earlier allows remote attackers to cause a denial of service (crash) via (1) a large number of connections with a negative Content-Length header, possibly triggering an integer signedness error, or (2) a large amount of data.  Assigned (20050219)  None (candidate not yet proposed)    View
11687  CVE-2005-0481  Candidate  TrackerCam 5.12 and earlier allows remote attackers to read log files via the fn parameter in a direct request to the ComGetLogFile.php3 script.  Assigned (20050219)  None (candidate not yet proposed)    View
11686  CVE-2005-0480  Candidate  Cross-site scripting (XSS) vulnerability in TrackerCam 5.12 and earlier allows remote attackers to inject arbitrary HTML or web script via the login request, which is recorded in a log file but not properly handled when the administrator views the log file.  Assigned (20050219)  None (candidate not yet proposed)    View

Page 18606 of 20943, showing 5 records out of 104715 total, starting on record 93026, ending on 93030

Actions