CVE List

Id CVE No. Status Description Phase Votes Comments Actions
15094  CVE-2005-3890  Candidate  Gadu-Gadu 7.20 allows remote attackers to cause a denial of service (crash and configuration loss) via a page with a large number of gg: URIs.  Assigned (20051129)  None (candidate not yet proposed)    View
15095  CVE-2005-3891  Candidate  Stack-based buffer overflow in Gadu-Gadu 7.20 allows remote attackers to cause a denial of service (crash) via an image filename between exactly 192 to 200 characters, which does not account for the "imgcache" string that is added to the end of the buffer.  Assigned (20051129)  None (candidate not yet proposed)    View
15096  CVE-2005-3892  Candidate  Gadu-Gadu 7.20 allows remote attackers to eavesdrop on a user via a web page that accesses the EasycallLite.oce ActiveX control, which can initiate an outgoing phone call and listen to the microphone.  Assigned (20051129)  None (candidate not yet proposed)    View
15097  CVE-2005-3893  Candidate  Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) user parameter in the Login action, and remote authenticated users via the (2) TicketID and (3) ArticleID parameters of the AgentTicketPlain action.  Assigned (20051129)  None (candidate not yet proposed)    View
15098  CVE-2005-3894  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) hex-encoded values in the QueueID parameter and (2) Action parameters.  Assigned (20051129)  None (candidate not yet proposed)    View

Page 18662 of 20943, showing 5 records out of 104715 total, starting on record 93306, ending on 93310

Actions