CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11680  CVE-2005-0474  Candidate  SQL injection vulnerability in the user_valid_crypt function in user.php in WebCalendar 0.9.45 allows remote attackers to execute arbitrary SQL commands via an encoded webcalendar_session cookie.  Assigned (20050219)  None (candidate not yet proposed)    View
11679  CVE-2005-0473  Candidate  The HTML parsing functions in Gaim before 1.1.3 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes "an invalid memory access," a different vulnerability than CVE-2005-0208.  Assigned (20050219)  None (candidate not yet proposed)    View
11678  CVE-2005-0472  Candidate  Gaim before 1.1.3 allows remote attackers to cause a denial of service (infinite loop) via malformed SNAC packets from (1) AIM or (2) ICQ.  Assigned (20050219)  None (candidate not yet proposed)    View
11677  CVE-2005-0471  Candidate  Sun Java JRE 1.1.x through 1.4.x writes temporary files with long filenames that become predictable on a file system that uses 8.3 style short names, which allows remote attackers to write arbitrary files to known locations and facilitates the exploitation of vulnerabilities in applications that rely on unpredictable file names.  Assigned (20050218)  None (candidate not yet proposed)    View
11676  CVE-2005-0470  Candidate  Buffer overflow in wpa_supplicant before 0.2.7 allows remote attackers to cause a denial of service (segmentation fault) via invalid EAPOL-Key packet data.  Assigned (20050218)  None (candidate not yet proposed)    View

Page 18608 of 20943, showing 5 records out of 104715 total, starting on record 93036, ending on 93040

Actions