CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
14682 | CVE-2005-3476 | Candidate | Unspecified vulnerability in HP OpenVMS Integrity 8.2-1 and 8.2, and OpenVMS Alpha 7.3-2 and 8.2, allows local users to cause a denial of service. | Assigned (20051102) | None (candidate not yet proposed) | View | |
14593 | CVE-2005-3387 | Candidate | The startup script in packages/RedHat/ntop.init in ntop before 3.2, when ntop.conf is writable by users besides root, creates temporary files insecurely, which allows remote attackers to execute arbitrary code. | Assigned (20051101) | None (candidate not yet proposed) | View | |
14594 | CVE-2005-3388 | Candidate | Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a "stacked array assignment." | Assigned (20051101) | None (candidate not yet proposed) | View | |
14595 | CVE-2005-3389 | Candidate | The parse_str function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when called with only one parameter, allows remote attackers to enable the register_globals directive via inputs that cause a request to be terminated due to the memory_limit setting, which causes PHP to set an internal flag that enables register_globals and allows attackers to exploit vulnerabilities in PHP applications that would otherwise be protected. | Assigned (20051101) | None (candidate not yet proposed) | View | |
14596 | CVE-2005-3390 | Candidate | The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to modify the GLOBALS array and bypass security protections of PHP applications via a multipart/form-data POST request with a "GLOBALS" fileupload field. | Assigned (20051101) | None (candidate not yet proposed) | View |
Page 18791 of 20943, showing 5 records out of 104715 total, starting on record 93951, ending on 93955