CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14160  CVE-2005-2954  Candidate  SQL injection vulnerability in password_reminder.php in ATutor before 1.5.1 pl1 allows remote attackers to execute arbitrary SQL commands via the email field.  Assigned (20050916)  None (candidate not yet proposed)    View
14161  CVE-2005-2955  Candidate  config.inc.php in ATutor 1.5.1, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which allows authenticated administrators or educators to execute arbitrary code by uploading files with other executable extensions such as .inc, .php4, or others.  Assigned (20050916)  None (candidate not yet proposed)    View
14162  CVE-2005-2956  Candidate  ATutor 1.5.1, and possibly earlier versions, stores temporary chat logs under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain user chat conversations via direct requests to those files.  Assigned (20050916)  None (candidate not yet proposed)    View
14163  CVE-2005-2957  Candidate  Stack-based buffer overflow in AVIRA Desktop for Windows 1.00.00.68 with AVPACK32.DLL 6.31.0.3, when archive scanning is enabled, allows remote attackers to execute arbitrary code via a long filename in an ACE archive.  Assigned (20050916)  None (candidate not yet proposed)    View
14123  CVE-2005-2917  Candidate  Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).  Assigned (20050915)  None (candidate not yet proposed)    View

Page 18899 of 20943, showing 5 records out of 104715 total, starting on record 94491, ending on 94495

Actions