CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11530 | CVE-2005-0324 | Candidate | Infinite Mobile Delivery Webmail 2.6 allows remote attackers to gain sensitive information via an HTTP request that contains invalid characters for a Windows foldername, which reveals the path in an error message. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11529 | CVE-2005-0323 | Candidate | Cross-site scripting (XSS) vulnerability in Infinite Mobile Delivery Webmail 2.6 allows remote attackers to inject arbitrary web script or HTML via the URL. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11528 | CVE-2005-0322 | Candidate | MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 and Mail Server 7.6.4r with Icewarp Mail Server 5.3.2 uses weak encryption in the (1) users.cfg, (2) settings.cfg, (3) users.dat or (4) user.dat files, which allows local users to extract the passwords. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11527 | CVE-2005-0321 | Candidate | MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allows remote authenticated users to gain sensitive information via an HTTP request to (1) calendar_d.html, (2) calendar_m.html, (3) calendar_w.html, or (4) calendar_y.html, which reveal the installation path. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11526 | CVE-2005-0320 | Candidate | Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to login.html, (2) accountid parameter to accountsettings_add.html, or the (3) note, (4) title, and (5) location fields to calendar.html. | Assigned (20050210) | None (candidate not yet proposed) | View |
Page 18638 of 20943, showing 5 records out of 104715 total, starting on record 93186, ending on 93190