CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11640  CVE-2005-0434  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Php-Nuke 7.5 allow remote attackers to inject arbitrary HTML or web script via (1) the newdownloadshowdays parameter in a NewDownloads operation or (2) the newlinkshowdays parameter in a NewLinks operation.  Assigned (20050215)  None (candidate not yet proposed)    View
11639  CVE-2005-0433  Candidate  Php-Nuke 7.5 allows remote attackers to determine the full path of the web server via invalid or missing arguments to (1) db.php, (2) mainfile.php, (3) Downloads/index.php, or (4) Web_Links/index.php, which lists the path in a PHP error message.  Assigned (20050215)  None (candidate not yet proposed)    View
11638  CVE-2005-0432  Candidate  BEA WebLogic Server 7.0 Service Pack 5 and earlier, and 8.1 Service Pack 3 and earlier, generates different login exceptions that suggest why an authentication attempt fails, which makes it easier for remote attackers to guess passwords via brute force attacks.  Assigned (20050215)  None (candidate not yet proposed)    View
11637  CVE-2005-0431  Candidate  Barracuda Spam Firewall 3.1.10 and earlier does not restrict the domains that white-listed domains can send mail to, which allows members of white-listed domains to use Barracuda as an open mail relay for spam.  Assigned (20050215)  None (candidate not yet proposed)    View
11636  CVE-2005-0430  Candidate  The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash the server via a long infostring, possibly triggering a buffer overflow.  Assigned (20050215)  None (candidate not yet proposed)    View

Page 18616 of 20943, showing 5 records out of 104715 total, starting on record 93076, ending on 93080

Actions