CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13577  CVE-2005-2371  Candidate  Directory traversal vulnerability in Oracle Reports 6.0, 6i, 9i, and 10g allows remote attackers to overwrite arbitrary files via (1) "..", (2) Windows drive letter (C:), and (3) absolute path sequences in the desname parameter. NOTE: this issue was probably fixed by REP06 in CPU Jan 2006, in which case it overlaps CVE-2006-0289.  Assigned (20050726)  None (candidate not yet proposed)    View
13578  CVE-2005-2372  Candidate  Oracle Forms 4.5 through 10g starts form executables from arbitrary directories and executes them as the Oracle or System user, which allows attackers to execute arbitrary code by uploading a malicious .fmx file and referencing it using an absolute pathname argument in the (1) form or (2) module parameters to f90servlet.  Assigned (20050726)  None (candidate not yet proposed)    View
13579  CVE-2005-2373  Candidate  Buffer overflow in SlimFTPd 3.15 and 3.16 allows remote authenticated users to execute arbitrary code via a long directory name to (1) LIST, (2) DELE or (3) RNFR commands.  Assigned (20050726)  None (candidate not yet proposed)    View
13580  CVE-2005-2374  Candidate  Belkin 54g wireless routers do not properly set an administrative password, which allows remote attackers to gain access via the (1) Telnet or (2) weba dministration interfaces.  Assigned (20050726)  None (candidate not yet proposed)    View
13581  CVE-2005-2375  Candidate  Format string vulnerability in Race Driver 1.20 and earlier allows remote attackers to cause a denial of service (application crash) via format string specifiers in a (1) nickname or (2) chat message.  Assigned (20050726)  None (candidate not yet proposed)    View

Page 1878 of 20943, showing 5 records out of 104715 total, starting on record 9386, ending on 9390

Actions