CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14172  CVE-2005-2966  Candidate  The Python SVG import plugin (diasvg_import.py) for DIA 0.94 and earlier allows user-assisted attackers to execute arbitrary commands via a crafted SVG file.  Assigned (20050919)  None (candidate not yet proposed)    View
14173  CVE-2005-2967  Candidate  Format string vulnerability in input_cdda.c in xine-lib 1-beta through 1-beta 3, 1-rc, 1.0 through 1.0.2, and 1.1.1 allows remote servers to execute arbitrary code via format string specifiers in metadata in CDDB server responses when the victim plays a CD.  Assigned (20050919)  None (candidate not yet proposed)    View
14174  CVE-2005-2968  Candidate  Firefox 1.0.6 and Mozilla 1.7.10 allows attackers to execute arbitrary commands via shell metacharacters in a URL that is provided to the browser on the command line, which is sent unfiltered to bash.  Assigned (20050919)  None (candidate not yet proposed)    View
14175  CVE-2005-2969  Candidate  The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.  Assigned (20050919)  None (candidate not yet proposed)    View
14176  CVE-2005-2970  Candidate  Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections.  Assigned (20050919)  None (candidate not yet proposed)    View

Page 18892 of 20943, showing 5 records out of 104715 total, starting on record 94456, ending on 94460

Actions