CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14356  CVE-2005-3150  Candidate  Format string vulnerability in the Log_Flush function in Weex 2.6.1.5, 2.6.1, and possibly other versions allows remote FTP servers to execute arbitrary code via format strings in filenames.  Assigned (20051005)  None (candidate not yet proposed)    View
14357  CVE-2005-3151  Candidate  Buffer overflow in blenderplay in Blender Player 2.37a allows attackers to execute arbitrary code via a long command line argument.  Assigned (20051005)  None (candidate not yet proposed)    View
14358  CVE-2005-3152  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the redir parameter to (1) cart.php or (2) index.php, or (3) the searchStr parameter in a viewCat action to index.php. Note: vectors (1) and (2) were later reported to affect 3.0.7-pl1.  Assigned (20051005)  None (candidate not yet proposed)    View
14359  CVE-2005-3153  Candidate  login.php in myBloggie 2.1.3 beta and earlier allows remote attackers to bypass a whitelist regular expression and conduct SQL injection attacks via a username parameter with SQL after a null character, which causes the whitelist check to succeed but injects the SQL into a query string, a different vulnerability than CVE-2005-2838. NOTE: it is possible that this is actually a bug in PHP code, in which case this should not be treated as a myBloggie vulnerability.  Assigned (20051005)  None (candidate not yet proposed)    View
14360  CVE-2005-3154  Candidate  Format string vulnerability in the logging functionality in BitDefender AntiVirus 7.2 through 9 allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in file or directory name.  Assigned (20051005)  None (candidate not yet proposed)    View

Page 18859 of 20943, showing 5 records out of 104715 total, starting on record 94291, ending on 94295

Actions