CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11665  CVE-2005-0459  Candidate  phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote attackers to determine the full path of the web root via a direct request to select_lang.lib.php, which reveals the path in a PHP error message.  Assigned (20050217)  None (candidate not yet proposed)    View
11664  CVE-2005-0458  Candidate  Cross-site scripting (XSS) vulnerability in contact_us.php in osCommerce 2.2-MS2 allows remote attackers to inject arbitrary web script or HTML via the enquiry parameter.  Assigned (20050217)  None (candidate not yet proposed)    View
11663  CVE-2005-0457  Candidate  Opera 7.54 and earlier on Gentoo Linux uses an insecure path for plugins, which could allow local users to gain privileges by inserting malicious libraries into the PORTAGE_TMPDIR (portage) temporary directory.  Assigned (20050217)  None (candidate not yet proposed)    View
11662  CVE-2005-0456  Candidate  Opera 7.54 and earlier does not properly validate base64 encoded binary data in a data: (RFC 2397) URL, which causes the URL to be obscured in a download dialog, which may allow remote attackers to trick users into executing arbitrary code.  Assigned (20050217)  None (candidate not yet proposed)    View
11661  CVE-2005-0455  Candidate  Stack-based buffer overflow in the CSmil1Parser::testAttributeFailed function in smlparse.cpp for RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1 allows remote attackers to execute arbitrary code via a .SMIL file with a large system-screen-size value.  Assigned (20050216)  None (candidate not yet proposed)    View

Page 18611 of 20943, showing 5 records out of 104715 total, starting on record 93051, ending on 93055

Actions