CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14149  CVE-2005-2943  Candidate  Stack-based buffer overflow in sendmail in XMail before 1.22 allows remote attackers to execute arbitrary code via a long -t command line option.  Assigned (20050915)  None (candidate not yet proposed)    View
14085  CVE-2005-2879  Candidate  Advansysperu Software USB Lock Auto-Protect (AP) 1.5 uses a weak encryption scheme to encrypt passwords, which allows local users to gain sensitive information and bypass USB interface protection.  Assigned (20050914)  None (candidate not yet proposed)    View
14086  CVE-2005-2880  Candidate  Multiple SQL injection vulnerabilities in phpCommunityCalendar 4.0.3, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via the (1) login field in login.php or (2) LocationID parameter to week.php.  Assigned (20050914)  None (candidate not yet proposed)    View
14087  CVE-2005-2881  Candidate  phpCommunityCalendar 4.0.3 allows remote attackers to bypass authentication and gain unauthorized access via a direct request to the admin directory.  Assigned (20050914)  None (candidate not yet proposed)    View
14088  CVE-2005-2882  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in phpCommunityCalendar 4.0.3, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the LocationID parameter to (1) thankyou.php or (2) day.php, font parameter to (3) calDaily.php, (4) calMonthly.php, (5) calMonthlyP.php, (6) calWeekly.php, (7) calWeeklyP.php, (8) calYearly.php, (9) calYearlyP.php, (10) day.php, or (11) week.php, or (12) CeTi, (13) Contact, (14) Description, (15) ShowAddress parameter to event.php, and other attack vectors.  Assigned (20050914)  None (candidate not yet proposed)    View

Page 18905 of 20943, showing 5 records out of 104715 total, starting on record 94521, ending on 94525

Actions