CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
14833 | CVE-2005-3629 | Candidate | initscripts in Red Hat Enterprise Linux 4 does not properly handle certain environment variables when /sbin/service is executed, which allows local users with sudo permissions for /sbin/service to gain root privileges via unknown vectors. | Assigned (20051116) | None (candidate not yet proposed) | View | |
14834 | CVE-2005-3630 | Candidate | Fedora Directory Server before 10 allows remote attackers to obtain sensitive information, such as the password from adm.conf via an IFRAME element, probably involving an Apache httpd.conf configuration that orders "allow" directives before "deny" directives. | Assigned (20051116) | None (candidate not yet proposed) | View | |
14835 | CVE-2005-3631 | Candidate | udev does not properly set permissions on certain files in /dev/input, which allows local users to obtain sensitive data that is entered at the console, such as user passwords. | Assigned (20051116) | None (candidate not yet proposed) | View | |
14836 | CVE-2005-3632 | Candidate | Multiple buffer overflows in pnmtopng in netpbm 10.0 and earlier allow attackers to execute arbitrary code via a crafted PNM file. | Assigned (20051116) | None (candidate not yet proposed) | View | |
2805 | CVE-2000-1238 | Candidate | BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters before the restricted pages. | Assigned (20051116) | None (candidate not yet proposed) | View |
Page 18764 of 20943, showing 5 records out of 104715 total, starting on record 93816, ending on 93820