CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11505  CVE-2005-0299  Candidate  Directory traversal vulnerability in GForge 3.3 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the (1) dir parameter to controller.php or (2) dir_name parameter to controlleroo.php.  Assigned (20050210)  None (candidate not yet proposed)    View
11504  CVE-2005-0298  Candidate  The DIRECTORY objects in Oracle 8i through Oracle 10g contain the location of a specific operating system directory, which allows users with read privileges to a DIRECTORY object to obtain sensitive information.  Assigned (20050210)  None (candidate not yet proposed)    View
11503  CVE-2005-0297  Candidate  SQL injection vulnerability in Oracle Database 9i and 10g allows remote attackers to execute arbitrary SQL commands and gain privileges.  Assigned (20050210)  None (candidate not yet proposed)    View
11502  CVE-2005-0296  Candidate  ** DISPUTED ** NOTE: this issue has been disputed by the vendor. The error module in Novell GroupWise WebAccess allows remote attackers who have not authenticated to read potentially sensitive information, such as the version, via an incorrect login and a modified (1) error or (2) modify parameter that returns template files or the "about" information page. NOTE: the vendor has disputed this issue.  Assigned (20050210)  None (candidate not yet proposed)    View
11501  CVE-2005-0295  Candidate  npptnt2.sys in nProtect Gameguard provides unrestricted I/O to any process that calls it, which allows local users to gain privileges.  Assigned (20050210)  None (candidate not yet proposed)    View

Page 18643 of 20943, showing 5 records out of 104715 total, starting on record 93211, ending on 93215

Actions