CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14470  CVE-2005-3264  Candidate  Cross-site scripting (XSS) vulnerability in thread.php for Zeroblog 1.1f and 1.2a allows remote attackers to inject arbitrary web script or HTML via the threadID parameter.  Assigned (20051020)  None (candidate not yet proposed)    View
14471  CVE-2005-3265  Candidate  Buffer overflow in Skype for Windows 1.1.x.0 through 1.4.x.83 allows remote attackers to execute arbitrary code via (1) callto:// and (2) skype:// links, or (3) a non-standard VCARD, possibly due to an underlying error in the SysUtils.WideFmtStr Delphi routine.  Assigned (20051020)  None (candidate not yet proposed)    View
14472  CVE-2005-3266  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-3265. Reason: this candidate is a duplicate of CVE-2005-3265; after initial reservation, the requester discovered that they had the same cause. Notes: All CVE users should reference CVE-2005-3265 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20051020)  None (candidate not yet proposed)    View
14473  CVE-2005-3267  Candidate  Integer overflow in Skype client before 1.4.x.84 on Windows, before 1.3.x.17 on Mac OS, before 1.2.x.18 on Linux, and 1.1.x.6 and earlier allows remote attackers to cause a denial of service (crash) via crafted network data with a large Object Counter value, which leads to a resultant heap-based buffer overflow.  Assigned (20051020)  None (candidate not yet proposed)    View
14474  CVE-2005-3268  Candidate  yiff server (yiff-server) 2.14.2 on Debian GNU/Linux runs as root and does not properly verify ownership of files that it opens, which allows local users to read arbitrary files.  Assigned (20051020)  None (candidate not yet proposed)    View

Page 18834 of 20943, showing 5 records out of 104715 total, starting on record 94166, ending on 94170

Actions