CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13587 | CVE-2005-2381 | Candidate | PHP Surveyor 0.98 allows remote attackers to obtain sensitive information via a direct request to (1) question.php, (2) survey.php, or (3) group.php in the root directory, a direct request to (4) database.php, (5) sessioncontrol.php, (6) html.php, (7) sessioncontrol.php, an invalid (8) qid parameter to dumpquestion.php, or an invalid lid parameter to (9) labels.php or (10) dumplabel.php, which reveal the path in an error message. | Assigned (20050726) | None (candidate not yet proposed) | View | |
13588 | CVE-2005-2382 | Candidate | Oray PeanutHull 3.0.1.0 and earlier does not properly drop SYSTEM privileges when launched from the system tray, which allows local users to gain privileges by accessing the Help functionality. | Assigned (20050726) | None (candidate not yet proposed) | View | |
13589 | CVE-2005-2383 | Candidate | SQL injection vulnerability in auth.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the user parameter in an HTTP POST request. | Assigned (20050726) | None (candidate not yet proposed) | View | |
13565 | CVE-2005-2359 | Candidate | The AES-XCBC-MAC algorithm in IPsec in FreeBSD 5.3 and 5.4, when used for authentication without other encryption, uses a constant key instead of the one that was assigned by the system administrator, which can allow remote attackers to spoof packets to establish an IPsec session. | Assigned (20050726) | None (candidate not yet proposed) | View | |
13566 | CVE-2005-2360 | Candidate | Unknown vulnerability in the LDAP dissector in Ethereal 0.8.5 through 0.10.11 allows remote attackers to cause a denial of service (free static memory and application crash) via unknown attack vectors. | Assigned (20050726) | None (candidate not yet proposed) | View |
Page 1880 of 20943, showing 5 records out of 104715 total, starting on record 9396, ending on 9400