CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14727  CVE-2005-3521  Candidate  SQL injection vulnerability in resetcore.php in e107 0.617 through 0.6173 allows remote attackers to execute arbitrary SQL commands, bypass authentication, and inject HTML or script via the (1) a_name parameter or (2) user field of the login page.  Assigned (20051106)  None (candidate not yet proposed)    View
14728  CVE-2005-3522  Candidate  Cross-site scripting (XSS) vulnerability in index.jsp in ManageEngine Netflow Analyzer 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the grDisp parameter.  Assigned (20051106)  None (candidate not yet proposed)    View
14706  CVE-2005-3500  Candidate  The tnef_attachment function in tnef.c for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via a crafted value in a CAB file that causes ClamAV to repeatedly scan the same block.  Assigned (20051105)  None (candidate not yet proposed)    View
14707  CVE-2005-3501  Candidate  The cabd_find function in cabd.c of the libmspack library (mspack) for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted CAB file that causes cabd_find to be called with a zero length.  Assigned (20051105)  None (candidate not yet proposed)    View
14708  CVE-2005-3502  Candidate  attachment_send.php in Cerberus Helpdesk allows remote attackers to view attachments and tickets of other users via a modified file_id parameter.  Assigned (20051105)  None (candidate not yet proposed)    View

Page 18775 of 20943, showing 5 records out of 104715 total, starting on record 93871, ending on 93875

Actions