CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14704  CVE-2005-3498  Candidate  IBM WebSphere Application Server 5.0.x before 5.02.15, 5.1.x before 5.1.1.8, and 6.x before fixpack V6.0.2.5, when session trace is enabled, records a full URL including the queryString in the trace logs when an application encodes a URL, which could allow attackers to obtain sensitive information.  Assigned (20051103)  None (candidate not yet proposed)    View
14705  CVE-2005-3499  Candidate  Frisk F-Prot Antivirus allows remote attackers to bypass protection via a ZIP file with a version header greater than 15, which prevents F-Prot from decompressing and analyzing the file.  Assigned (20051103)  None (candidate not yet proposed)    View
14634  CVE-2005-3428  Candidate  Cross-site scripting (XSS) vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to inject arbitrary web script or HTML via a message body.  Assigned (20051102)  None (candidate not yet proposed)    View
14635  CVE-2005-3429  Candidate  Rockliffe MailSite Express before 6.1.22, with the option to save login information enabled, saves user passwords in plaintext in cookies, which allows local users to obtain passwords by reading the cookie file, or remote attackers to obtain the cookies via cross-site scripting (XSS) vulnerabilities.  Assigned (20051102)  None (candidate not yet proposed)    View
14636  CVE-2005-3430  Candidate  Incomplete blacklist vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions, such as (1) .unk, (2) .asa, and possibly (3) .htr and (4) .aspx, which are not filtered like the .asp extension.  Assigned (20051102)  None (candidate not yet proposed)    View

Page 18781 of 20943, showing 5 records out of 104715 total, starting on record 93901, ending on 93905

Actions