CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
14553 | CVE-2005-3347 | Candidate | Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egrouwpware before 1.0.0.009, allow remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) sensor_program parameter or the (2) _SERVER[HTTP_ACCEPT_LANGUAGE] parameter, which overwrites an internal variable, a variant of CVE-2003-0536. NOTE: due to a typo in an advisory, an issue in osh was inadvertently linked to this identifier; the proper identifier for the osh issue is CVE-2005-3346. | Assigned (20051027) | None (candidate not yet proposed) | View | |
14554 | CVE-2005-3348 | Candidate | HTTP response splitting vulnerability in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egroupware before 1.0.0.009, allows remote attackers to spoof web content and poison web caches via CRLF sequences in the charset parameter. | Assigned (20051027) | None (candidate not yet proposed) | View | |
14555 | CVE-2005-3349 | Candidate | GNU Gnump3d before 2.9.8 allows local users to modify or delete arbitrary files via a symlink attack on the index.lok temporary file. | Assigned (20051027) | None (candidate not yet proposed) | View | |
14556 | CVE-2005-3350 | Candidate | libungif library before 4.1.0 allows attackers to corrupt memory and possibly execute arbitrary code via a crafted GIF file that leads to an out-of-bounds write. | Assigned (20051027) | None (candidate not yet proposed) | View | |
14557 | CVE-2005-3351 | Candidate | SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl. | Assigned (20051027) | None (candidate not yet proposed) | View |
Page 18811 of 20943, showing 5 records out of 104715 total, starting on record 94051, ending on 94055