CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14823  CVE-2005-3619  Candidate  Cross-site scripting (XSS) vulnerability in the management interface for VMware ESX 2.5.x before 2.5.2 upgrade patch 2, 2.1.x before 2.1.2 upgrade patch 6, and 2.0.x before 2.0.1 upgrade patch 6 allows remote attackers to inject arbitrary web script or HTML via messages that are not sanitized when viewing syslog log files.  Assigned (20051116)  None (candidate not yet proposed)    View
14824  CVE-2005-3620  Candidate  The management interface for VMware ESX Server 2.0.x before 2.0.2 patch 1, 2.1.x before 2.1.3 patch 1, and 2.x before 2.5.3 patch 2 records passwords in cleartext in URLs that are stored in world-readable web server log files, which allows local users to gain privileges.  Assigned (20051116)  None (candidate not yet proposed)    View
14825  CVE-2005-3621  Candidate  CRLF injection vulnerability in phpMyAdmin before 2.6.4-pl4 allows remote attackers to conduct HTTP response splitting attacks via unspecified scripts.  Assigned (20051116)  None (candidate not yet proposed)    View
14826  CVE-2005-3622  Candidate  phpMyAdmin 2.7.0-beta1 and earlier allows remote attackers to obtain the full path of the server via direct requests to multiple scripts in the libraries directory.  Assigned (20051116)  None (candidate not yet proposed)    View
14827  CVE-2005-3623  Candidate  nfs2acl.c in the Linux kernel 2.6.14.4 does not check for MAY_SATTR privilege before setting access controls (ACL) on files on exported NFS filesystems, which allows remote attackers to bypass ACLs for readonly mounted NFS filesystems.  Assigned (20051116)  None (candidate not yet proposed)    View

Page 18762 of 20943, showing 5 records out of 104715 total, starting on record 93806, ending on 93810

Actions