CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14637  CVE-2005-3431  Candidate  Absolute path traversal vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to read arbitrary files via a full pathname in the AttachPath field of a mail message under composition.  Assigned (20051102)  None (candidate not yet proposed)    View
14638  CVE-2005-3432  Candidate  MiniGal 2 (MG2) 0.5.1 allows remote attackers to list password protected images via a request to index.php with the list parameter set to * (wildcard) and the page parameter set to all.  Assigned (20051102)  None (candidate not yet proposed)    View
14639  CVE-2005-3433  Candidate  Buffer overflow in Mirabilis ICQ 2003a allows user-assisted attackers to execute arbitrary code by convincing a user to enter long strings into the First Name and Last Name fields.  Assigned (20051102)  None (candidate not yet proposed)    View
14640  CVE-2005-3434  Candidate  Archilles Newsworld before 1.5.0-rc1 stores (1) account.nwd and (2) session.nwd under the web root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames, hashed passwords, and session IDs, and gain privileges.  Assigned (20051102)  None (candidate not yet proposed)    View
14641  CVE-2005-3435  Candidate  admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for example through another Newsworld vulnerability, and specifying the hash in the pwd argument.  Assigned (20051102)  None (candidate not yet proposed)    View

Page 18782 of 20943, showing 5 records out of 104715 total, starting on record 93906, ending on 93910

Actions