CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14382  CVE-2005-3176  Candidate  Microsoft Windows 2000 before Update Rollup 1 for SP4 does not record the IP address of a Windows Terminal Services client in a security log event if the client connects successfully, which could make it easier for attackers to escape detection.  Assigned (20051006)  None (candidate not yet proposed)    View
14383  CVE-2005-3177  Candidate  CHKDSK in Microsoft Windows 2000 before Update Rollup 1 for SP4, Windows XP, and Windows Server 2003, when running in fix mode, does not properly handle security descriptors if the master file table contains a large number of files or if the descriptors do not satisfy certain NTFS conventions, which could cause ACLs for some files to be reverted to less secure defaults, or cause security descriptors to be removed.  Assigned (20051006)  None (candidate not yet proposed)    View
14343  CVE-2005-3137  Candidate  The (1) cfmailfilter and (2) cfcron.in files for cfengine 1.6.5 allow local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2005-2960.  Assigned (20051005)  None (candidate not yet proposed)    View
14344  CVE-2005-3138  Candidate  Bugzilla 2.18rc1 through 2.18.3, 2.19 through 2.20rc2, and 2.21 allows remote attackers to obtain sensitive information such as the list of installed products via the config.cgi file, which is accessible even when the requirelogin parameter is set.  Assigned (20051005)  None (candidate not yet proposed)    View
14345  CVE-2005-3139  Candidate  Bugzilla 2.19.1 through 2.20rc2 and 2.21, with user matching turned on in substring mode, allows attackers to list all users whose names match an arbitrary substring, even when the usevisibilitygroups parameter is set.  Assigned (20051005)  None (candidate not yet proposed)    View

Page 18856 of 20943, showing 5 records out of 104715 total, starting on record 94276, ending on 94280

Actions