CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
14494 | CVE-2005-3288 | Candidate | Mailsite Express allows remote attackers to upload and execute files with executable extensions such as ASP by attaching the file using the "compose page" feature, then accessing the file from the cache directory before saving or sending the message. | Assigned (20051023) | None (candidate not yet proposed) | View | |
14495 | CVE-2005-3289 | Candidate | LSCFG in IBM AIX 5.2 and 5.3 does not create temporary files securely, which allows local users to corrupt /etc/passwd and possibly other system files via the trace file. | Assigned (20051023) | None (candidate not yet proposed) | View | |
14496 | CVE-2005-3290 | Candidate | SQL injection vulnerability in Accelerated Mortgage Manager allows remote attackers to execute arbitrary SQL commands via the password field. | Assigned (20051023) | None (candidate not yet proposed) | View | |
14497 | CVE-2005-3291 | Candidate | Stani"s Python Editor (SPE) 0.7.5 is installed with world-writable permissions, which allows local users to gain privileges by modifying executable files. | Assigned (20051023) | None (candidate not yet proposed) | View | |
14498 | CVE-2005-3292 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Xeobook 0.93 allow remote attackers to inject arbitrary web script or HTML via Javascript events in tages such as <b>. | Assigned (20051023) | None (candidate not yet proposed) | View |
Page 18830 of 20943, showing 5 records out of 104715 total, starting on record 94146, ending on 94150