CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14060  CVE-2005-2854  Candidate  CRLF injection vulnerability in thesitewizard.com chfeedback.pl Feedback Form Perl Script 2.0.1 allows remote attackers to use the script as a mail relay (spam proxy) via CRLF sequences in the (1) name or (2) email fields, which are injected into mail headers.  Assigned (20050908)  None (candidate not yet proposed)    View
14061  CVE-2005-2855  Candidate  Cross-site scripting (XSS) vulnerability in Unclassified NewsBoard 1.5.3 allows remote attackers to inject arbitrary web script or HTML via the description field.  Assigned (20050908)  None (candidate not yet proposed)    View
14062  CVE-2005-2856  Candidate  Stack-based buffer overflow in the WinACE UNACEV2.DLL third-party compression utility before 2.6.0.0, as used in multiple products including (1) ALZip 5.51 through 6.11, (2) Servant Salamander 2.0 and 2.5 Beta 1, (3) WinHKI 1.66 and 1.67, (4) ExtractNow 3.x, (5) Total Commander 6.53, (6) Anti-Trojan 5.5.421, (7) PowerArchiver before 9.61, (8) UltimateZip 2.7,1, 3.0.3, and 3.1b, (9) Where Is It (WhereIsIt) 3.73.501, (10) FilZip 3.04, (11) IZArc 3.5 beta3, (12) Eazel 1.0, (13) Rising Antivirus 18.27.21 and earlier, (14) AutoMate 6.1.0.0, (15) BitZipper 4.1 SR-1, (16) ZipTV, and other products, allows user-assisted attackers to execute arbitrary code via a long filename in an ACE archive.  Assigned (20050908)  None (candidate not yet proposed)    View
14063  CVE-2005-2857  Candidate  Free SMTP Server 2.2 allows remote attackers to use the server as an open mail relay (spam proxy).  Assigned (20050908)  None (candidate not yet proposed)    View
14064  CVE-2005-2858  Candidate  The Fetch.FetchContact.1 ActiveX control (Fetch.dll) for Rediff Bol 7.0 allows remote attackers to read the Windows Address Book via the FullAddressBook method.  Assigned (20050908)  None (candidate not yet proposed)    View

Page 18917 of 20943, showing 5 records out of 104715 total, starting on record 94581, ending on 94585

Actions