CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14553  CVE-2005-3347  Candidate  Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egrouwpware before 1.0.0.009, allow remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) sensor_program parameter or the (2) _SERVER[HTTP_ACCEPT_LANGUAGE] parameter, which overwrites an internal variable, a variant of CVE-2003-0536. NOTE: due to a typo in an advisory, an issue in osh was inadvertently linked to this identifier; the proper identifier for the osh issue is CVE-2005-3346.  Assigned (20051027)  None (candidate not yet proposed)    View
14554  CVE-2005-3348  Candidate  HTTP response splitting vulnerability in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egroupware before 1.0.0.009, allows remote attackers to spoof web content and poison web caches via CRLF sequences in the charset parameter.  Assigned (20051027)  None (candidate not yet proposed)    View
14555  CVE-2005-3349  Candidate  GNU Gnump3d before 2.9.8 allows local users to modify or delete arbitrary files via a symlink attack on the index.lok temporary file.  Assigned (20051027)  None (candidate not yet proposed)    View
14556  CVE-2005-3350  Candidate  libungif library before 4.1.0 allows attackers to corrupt memory and possibly execute arbitrary code via a crafted GIF file that leads to an out-of-bounds write.  Assigned (20051027)  None (candidate not yet proposed)    View
14557  CVE-2005-3351  Candidate  SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl.  Assigned (20051027)  None (candidate not yet proposed)    View

Page 18811 of 20943, showing 5 records out of 104715 total, starting on record 94051, ending on 94055

Actions