CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11690 | CVE-2005-0484 | Candidate | Format string vulnerability in gprostats for GProFTPD before 8.1.9 may allow remote attackers to execute arbitrary code via an FTP transfer with a crafted filename that causes format string specifiers to be inserted into the ProFTPD transfer log. | Assigned (20050219) | None (candidate not yet proposed) | View | |
11689 | CVE-2005-0483 | Candidate | Multiple directory traversal vulnerabilities in sitenfo.sh, sitezipchk.sh, and siteziplist.sh in Glftpd 1.26 to 2.00 allow remote authenticated users to (1) determine the existence of arbitrary files, (2) list files in restricted directories, or (3) read arbitrary files from within ZIP or gzip files, via .. (dot dot) sequences and globbing ("*") characters in a SITE NFO command. | Assigned (20050219) | None (candidate not yet proposed) | View | |
11688 | CVE-2005-0482 | Candidate | TrackerCam 5.12 and earlier allows remote attackers to cause a denial of service (crash) via (1) a large number of connections with a negative Content-Length header, possibly triggering an integer signedness error, or (2) a large amount of data. | Assigned (20050219) | None (candidate not yet proposed) | View | |
11687 | CVE-2005-0481 | Candidate | TrackerCam 5.12 and earlier allows remote attackers to read log files via the fn parameter in a direct request to the ComGetLogFile.php3 script. | Assigned (20050219) | None (candidate not yet proposed) | View | |
11686 | CVE-2005-0480 | Candidate | Cross-site scripting (XSS) vulnerability in TrackerCam 5.12 and earlier allows remote attackers to inject arbitrary HTML or web script via the login request, which is recorded in a log file but not properly handled when the administrator views the log file. | Assigned (20050219) | None (candidate not yet proposed) | View |
Page 18606 of 20943, showing 5 records out of 104715 total, starting on record 93026, ending on 93030