CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14212  CVE-2005-3006  Candidate  The mail client in Opera before 8.50 opens attached files from the user"s cache directory without warning the user, which might allow remote attackers to inject arbitrary web script and spoof attachment filenames.  Assigned (20050921)  None (candidate not yet proposed)    View
14213  CVE-2005-3007  Candidate  Opera before 8.50 allows remote attackers to spoof the content type of files via a filename with a trailing "." (dot), which might allow remote attackers to trick users into processing dangerous content.  Assigned (20050921)  None (candidate not yet proposed)    View
14214  CVE-2005-3008  Candidate  Tofu 0.2 allows remote attackers to execute arbitrary Python code via crafted pickled objects, which Tofu unpickles and executes.  Assigned (20050921)  None (candidate not yet proposed)    View
14215  CVE-2005-3009  Candidate  Cross-site scripting (XSS) vulnerability in CuteNews allows remote attackers to inject arbitrary web script or HTML via the mod parameter to index.php.  Assigned (20050921)  None (candidate not yet proposed)    View
14216  CVE-2005-3010  Candidate  Direct static code injection vulnerability in the flood protection feature in inc/shows.inc.php in CuteNews 1.4.0 and earlier allows remote attackers to execute arbitrary PHP code via the HTTP_CLIENT_IP header (Client-Ip), which is injected into data/flood.db.php.  Assigned (20050921)  None (candidate not yet proposed)    View

Page 18883 of 20943, showing 5 records out of 104715 total, starting on record 94411, ending on 94415

Actions