CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11295  CVE-2005-0089  Candidate  The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instance method to register an object without a _dispatch method, allows remote attackers to read or modify globals of the associated module, and possibly execute arbitrary code, via dotted attributes.  Assigned (20050118)  None (candidate not yet proposed)    View
11294  CVE-2005-0088  Candidate  The publisher handler for mod_python 2.7.8 and earlier allows remote attackers to obtain access to restricted objects via a crafted URL.  Assigned (20050118)  None (candidate not yet proposed)    View
11293  CVE-2005-0087  Candidate  The alsa-lib package in Red Hat Linux 4 disables stack protection for the libasound.so library, which makes it easier for attackers to execute arbitrary code if there are other vulnerabilities in the library.  Assigned (20050118)  None (candidate not yet proposed)    View
11292  CVE-2005-0086  Candidate  Heap-based buffer overflow in less in Red Hat Enterprise Linux 3 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted file, as demonstrated using the UTF-8 locale.  Assigned (20050118)  None (candidate not yet proposed)    View
11291  CVE-2005-0085  Candidate  Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.  Assigned (20050118)  None (candidate not yet proposed)    View

Page 18685 of 20943, showing 5 records out of 104715 total, starting on record 93421, ending on 93425

Actions