CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14494  CVE-2005-3288  Candidate  Mailsite Express allows remote attackers to upload and execute files with executable extensions such as ASP by attaching the file using the "compose page" feature, then accessing the file from the cache directory before saving or sending the message.  Assigned (20051023)  None (candidate not yet proposed)    View
14495  CVE-2005-3289  Candidate  LSCFG in IBM AIX 5.2 and 5.3 does not create temporary files securely, which allows local users to corrupt /etc/passwd and possibly other system files via the trace file.  Assigned (20051023)  None (candidate not yet proposed)    View
14496  CVE-2005-3290  Candidate  SQL injection vulnerability in Accelerated Mortgage Manager allows remote attackers to execute arbitrary SQL commands via the password field.  Assigned (20051023)  None (candidate not yet proposed)    View
14497  CVE-2005-3291  Candidate  Stani"s Python Editor (SPE) 0.7.5 is installed with world-writable permissions, which allows local users to gain privileges by modifying executable files.  Assigned (20051023)  None (candidate not yet proposed)    View
14498  CVE-2005-3292  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Xeobook 0.93 allow remote attackers to inject arbitrary web script or HTML via Javascript events in tages such as <b>.  Assigned (20051023)  None (candidate not yet proposed)    View

Page 18830 of 20943, showing 5 records out of 104715 total, starting on record 94146, ending on 94150

Actions