CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14682  CVE-2005-3476  Candidate  Unspecified vulnerability in HP OpenVMS Integrity 8.2-1 and 8.2, and OpenVMS Alpha 7.3-2 and 8.2, allows local users to cause a denial of service.  Assigned (20051102)  None (candidate not yet proposed)    View
14593  CVE-2005-3387  Candidate  The startup script in packages/RedHat/ntop.init in ntop before 3.2, when ntop.conf is writable by users besides root, creates temporary files insecurely, which allows remote attackers to execute arbitrary code.  Assigned (20051101)  None (candidate not yet proposed)    View
14594  CVE-2005-3388  Candidate  Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a "stacked array assignment."  Assigned (20051101)  None (candidate not yet proposed)    View
14595  CVE-2005-3389  Candidate  The parse_str function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when called with only one parameter, allows remote attackers to enable the register_globals directive via inputs that cause a request to be terminated due to the memory_limit setting, which causes PHP to set an internal flag that enables register_globals and allows attackers to exploit vulnerabilities in PHP applications that would otherwise be protected.  Assigned (20051101)  None (candidate not yet proposed)    View
14596  CVE-2005-3390  Candidate  The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to modify the GLOBALS array and bypass security protections of PHP applications via a multipart/form-data POST request with a "GLOBALS" fileupload field.  Assigned (20051101)  None (candidate not yet proposed)    View

Page 18791 of 20943, showing 5 records out of 104715 total, starting on record 93951, ending on 93955

Actions