CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14586  CVE-2005-3380  Candidate  Multiple interpretation error in Panda Titanium 2005 4.02.01 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by applications on the end system, as demonstrated by a "triple headed" program that contains EXE, EML, and HTML content, aka the "magic byte bug."  Assigned (20051029)  None (candidate not yet proposed)    View
14587  CVE-2005-3381  Candidate  Multiple interpretation error in Ukrainian National Antivirus (UNA) 1.83.2.16 with kernel 265 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by applications on the end system, as demonstrated by a "triple headed" program that contains EXE, EML, and HTML content, aka the "magic byte bug."  Assigned (20051029)  None (candidate not yet proposed)    View
14588  CVE-2005-3382  Candidate  Multiple interpretation error in Sophos 3.91 with the 2.28.4 engine allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by applications on the end system, as demonstrated by a "triple headed" program that contains EXE, EML, and HTML content, aka the "magic byte bug."  Assigned (20051029)  None (candidate not yet proposed)    View
14589  CVE-2005-3383  Candidate  SQL injection vulnerability in Techno Dreams Announcement script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp.  Assigned (20051029)  None (candidate not yet proposed)    View
14590  CVE-2005-3384  Candidate  SQL injection vulnerability in Techno Dreams Guest Book script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp.  Assigned (20051029)  None (candidate not yet proposed)    View

Page 18803 of 20943, showing 5 records out of 104715 total, starting on record 94011, ending on 94015

Actions