CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14591  CVE-2005-3385  Candidate  SQL injection vulnerability in Techno Dreams Mailing List script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp.  Assigned (20051029)  None (candidate not yet proposed)    View
6506  CVE-2002-2124  Candidate  The recvn and sendn functions in nylon 0.2 do not check when the recv function call returns 0, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) by closing the connection while recv is executing.  Assigned (20051028)  None (candidate not yet proposed)    View
8057  CVE-2003-1233  Candidate  Pedestal Software Integrity Protection Driver (IPD) 1.3 and earlier allows privileged attackers, such as rootkits, to bypass file access restrictions to the Windows kernel by using the NtCreateSymbolicLinkObject function to create a symbolic link to (1) DevicePhysicalMemory or (2) to a drive letter using the subst command.  Assigned (20051028)  None (candidate not yet proposed)    View
14568  CVE-2005-3362  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-3153. Reason: This candidate is a reservation duplicate of CVE-2005-3153. Notes: All CVE users should reference CVE-2005-3153 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20051028)  None (candidate not yet proposed)    View
14522  CVE-2005-3316  Candidate  The installation of ON Symantec Discovery 4.5.x and Symantec Discovery 6.0 creates the (1) DiscoveryWeb and (2) DiscoveryRO database accounts with null passwords, which could allow attackers to gain privileges or prevent Discovery from running by setting another password.  Assigned (20051027)  None (candidate not yet proposed)    View

Page 18804 of 20943, showing 5 records out of 104715 total, starting on record 94016, ending on 94020

Actions