CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11575  CVE-2005-0369  Candidate  Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a packet with a large (1) descriptor ID or (2) claim_id, which exceeds the boundaries of an array.  Assigned (20050211)  None (candidate not yet proposed)    View
11574  CVE-2005-0368  Candidate  Multiple SQL injection vulnerabilities in CMScore allow remote attackers to execute arbitrary SQL commands via the (1) EntryID or (2) searchterm parameter to index.php, or (3) username parameter to authenticate.php.  Assigned (20050211)  None (candidate not yet proposed)    View
11573  CVE-2005-0367  Candidate  Multiple directory traversal vulnerabilities in ArGoSoft Mail Server 1.8.7.3 allow remote authenticated users to read, delete, or upload arbitrary files via a .. (dot dot) in (1) the filename of an e-mail attachment, (2) the _msgatt.rec file, (3) and the /msg, /delete, /folderadd, and /folderdelete operations for the Folder parameter.  Assigned (20050211)  None (candidate not yet proposed)    View
11572  CVE-2005-0366  Candidate  The integrity check feature in OpenPGP, when handling a message that was encrypted using cipher feedback (CFB) mode, allows remote attackers to recover part of the plaintext via a chosen-ciphertext attack when the first 2 bytes of a message block are known, and an oracle or other mechanism is available to determine whether an integrity check failed.  Assigned (20050211)  None (candidate not yet proposed)    View
11571  CVE-2005-0365  Candidate  The dcopidlng script in KDE 3.2.x and 3.3.x creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.  Assigned (20050211)  None (candidate not yet proposed)    View

Page 18629 of 20943, showing 5 records out of 104715 total, starting on record 93141, ending on 93145

Actions