CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14504  CVE-2005-3298  Candidate  Multiple buffer overflows in OpenWBEM on SuSE Linux 9 allow remote attackers to execute arbitrary code via unknown vectors.  Assigned (20051023)  None (candidate not yet proposed)    View
14505  CVE-2005-3299  Candidate  PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array.  Assigned (20051023)  None (candidate not yet proposed)    View
14506  CVE-2005-3300  Candidate  The register_globals emulation layer in grab_globals.php for phpMyAdmin before 2.6.4-pl3 does not perform safety checks on values in the _FILES array for uploaded files, which allows remote attackers to include arbitrary files by using direct requests to library scripts that do not use grab_globals.php, then modifying certain configuration values for the theme.  Assigned (20051023)  None (candidate not yet proposed)    View
14507  CVE-2005-3301  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) left.php, (2) queryframe.php, or (3) server_databases.php.  Assigned (20051023)  None (candidate not yet proposed)    View
14483  CVE-2005-3277  Candidate  The LPD service in HP-UX 10.20 11.11 (11i) and earlier allows remote attackers to execute arbitrary code via shell metacharacters ("`" or single backquote) in a request that is not properly handled when an error occurs, as demonstrated by killing the connection, a different vulnerability than CVE-2002-1473.  Assigned (20051021)  None (candidate not yet proposed)    View

Page 18832 of 20943, showing 5 records out of 104715 total, starting on record 94156, ending on 94160

Actions