CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
14727 | CVE-2005-3521 | Candidate | SQL injection vulnerability in resetcore.php in e107 0.617 through 0.6173 allows remote attackers to execute arbitrary SQL commands, bypass authentication, and inject HTML or script via the (1) a_name parameter or (2) user field of the login page. | Assigned (20051106) | None (candidate not yet proposed) | View | |
14728 | CVE-2005-3522 | Candidate | Cross-site scripting (XSS) vulnerability in index.jsp in ManageEngine Netflow Analyzer 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the grDisp parameter. | Assigned (20051106) | None (candidate not yet proposed) | View | |
14706 | CVE-2005-3500 | Candidate | The tnef_attachment function in tnef.c for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via a crafted value in a CAB file that causes ClamAV to repeatedly scan the same block. | Assigned (20051105) | None (candidate not yet proposed) | View | |
14707 | CVE-2005-3501 | Candidate | The cabd_find function in cabd.c of the libmspack library (mspack) for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted CAB file that causes cabd_find to be called with a zero length. | Assigned (20051105) | None (candidate not yet proposed) | View | |
14708 | CVE-2005-3502 | Candidate | attachment_send.php in Cerberus Helpdesk allows remote attackers to view attachments and tickets of other users via a modified file_id parameter. | Assigned (20051105) | None (candidate not yet proposed) | View |
Page 18775 of 20943, showing 5 records out of 104715 total, starting on record 93871, ending on 93875