CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
15094 | CVE-2005-3890 | Candidate | Gadu-Gadu 7.20 allows remote attackers to cause a denial of service (crash and configuration loss) via a page with a large number of gg: URIs. | Assigned (20051129) | None (candidate not yet proposed) | View | |
15095 | CVE-2005-3891 | Candidate | Stack-based buffer overflow in Gadu-Gadu 7.20 allows remote attackers to cause a denial of service (crash) via an image filename between exactly 192 to 200 characters, which does not account for the "imgcache" string that is added to the end of the buffer. | Assigned (20051129) | None (candidate not yet proposed) | View | |
15096 | CVE-2005-3892 | Candidate | Gadu-Gadu 7.20 allows remote attackers to eavesdrop on a user via a web page that accesses the EasycallLite.oce ActiveX control, which can initiate an outgoing phone call and listen to the microphone. | Assigned (20051129) | None (candidate not yet proposed) | View | |
15097 | CVE-2005-3893 | Candidate | Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) user parameter in the Login action, and remote authenticated users via the (2) TicketID and (3) ArticleID parameters of the AgentTicketPlain action. | Assigned (20051129) | None (candidate not yet proposed) | View | |
15098 | CVE-2005-3894 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) hex-encoded values in the QueueID parameter and (2) Action parameters. | Assigned (20051129) | None (candidate not yet proposed) | View |
Page 18662 of 20943, showing 5 records out of 104715 total, starting on record 93306, ending on 93310