CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11665 | CVE-2005-0459 | Candidate | phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote attackers to determine the full path of the web root via a direct request to select_lang.lib.php, which reveals the path in a PHP error message. | Assigned (20050217) | None (candidate not yet proposed) | View | |
11664 | CVE-2005-0458 | Candidate | Cross-site scripting (XSS) vulnerability in contact_us.php in osCommerce 2.2-MS2 allows remote attackers to inject arbitrary web script or HTML via the enquiry parameter. | Assigned (20050217) | None (candidate not yet proposed) | View | |
11663 | CVE-2005-0457 | Candidate | Opera 7.54 and earlier on Gentoo Linux uses an insecure path for plugins, which could allow local users to gain privileges by inserting malicious libraries into the PORTAGE_TMPDIR (portage) temporary directory. | Assigned (20050217) | None (candidate not yet proposed) | View | |
11662 | CVE-2005-0456 | Candidate | Opera 7.54 and earlier does not properly validate base64 encoded binary data in a data: (RFC 2397) URL, which causes the URL to be obscured in a download dialog, which may allow remote attackers to trick users into executing arbitrary code. | Assigned (20050217) | None (candidate not yet proposed) | View | |
11661 | CVE-2005-0455 | Candidate | Stack-based buffer overflow in the CSmil1Parser::testAttributeFailed function in smlparse.cpp for RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1 allows remote attackers to execute arbitrary code via a .SMIL file with a large system-screen-size value. | Assigned (20050216) | None (candidate not yet proposed) | View |
Page 18611 of 20943, showing 5 records out of 104715 total, starting on record 93051, ending on 93055