CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11670  CVE-2005-0464  Candidate  gr_osview in SGI IRIX 6.5.22, and possibly other 6.5 versions, does not drop privileges when opening description files while in debug mode, which allows local users to read a line from arbitrary files via the -d and -D options, which prints the line as a formatting error.  Assigned (20050218)  None (candidate not yet proposed)    View
11669  CVE-2005-0463  Candidate  Unknown "major security flaws" in Ulog-php before 1.0, related to input validation, have unknown impact and attack vectors, probably related to SQL injection vulnerabilities in (1) host.php, (2) port.php, and (3) index.php.  Assigned (20050217)  None (candidate not yet proposed)    View
11668  CVE-2005-0462  Candidate  Cross-site scripting (XSS) vulnerability in MercuryBoard 1.0.x and 1.1.x allows remote attackers to inject arbitrary HTML and web script via the f parameter.  Assigned (20050217)  None (candidate not yet proposed)    View
11667  CVE-2005-0461  Candidate  Unknown vulnerability in NewsBruiser 2.x before 2.6.1 allows remote attackers to "take actions on comments."  Assigned (20050217)  None (candidate not yet proposed)    View
11666  CVE-2005-0460  Candidate  index.php in MercuryBoard 1.0.x and 1.1.x allows remote attackers to obtain sensitive information by setting the debug parameter.  Assigned (20050217)  None (candidate not yet proposed)    View

Page 18610 of 20943, showing 5 records out of 104715 total, starting on record 93046, ending on 93050

Actions