CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13577 | CVE-2005-2371 | Candidate | Directory traversal vulnerability in Oracle Reports 6.0, 6i, 9i, and 10g allows remote attackers to overwrite arbitrary files via (1) "..", (2) Windows drive letter (C:), and (3) absolute path sequences in the desname parameter. NOTE: this issue was probably fixed by REP06 in CPU Jan 2006, in which case it overlaps CVE-2006-0289. | Assigned (20050726) | None (candidate not yet proposed) | View | |
13578 | CVE-2005-2372 | Candidate | Oracle Forms 4.5 through 10g starts form executables from arbitrary directories and executes them as the Oracle or System user, which allows attackers to execute arbitrary code by uploading a malicious .fmx file and referencing it using an absolute pathname argument in the (1) form or (2) module parameters to f90servlet. | Assigned (20050726) | None (candidate not yet proposed) | View | |
13579 | CVE-2005-2373 | Candidate | Buffer overflow in SlimFTPd 3.15 and 3.16 allows remote authenticated users to execute arbitrary code via a long directory name to (1) LIST, (2) DELE or (3) RNFR commands. | Assigned (20050726) | None (candidate not yet proposed) | View | |
13580 | CVE-2005-2374 | Candidate | Belkin 54g wireless routers do not properly set an administrative password, which allows remote attackers to gain access via the (1) Telnet or (2) weba dministration interfaces. | Assigned (20050726) | None (candidate not yet proposed) | View | |
13581 | CVE-2005-2375 | Candidate | Format string vulnerability in Race Driver 1.20 and earlier allows remote attackers to cause a denial of service (application crash) via format string specifiers in a (1) nickname or (2) chat message. | Assigned (20050726) | None (candidate not yet proposed) | View |
Page 1878 of 20943, showing 5 records out of 104715 total, starting on record 9386, ending on 9390