CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
14009 | CVE-2005-2803 | Candidate | Cross-site scripting (XSS) vulnerability in Hiki 0.8.1 to 0.8.2 allows remote attackers to inject arbitrary web script or HTML via a page name in a Login link, a different vulnerability than CVE-2005-2336. | Assigned (20050906) | None (candidate not yet proposed) | View | |
14010 | CVE-2005-2804 | Candidate | Integer overflow in the registry parsing code in GroupWise 6.5.3, and possibly earlier version, allows remote attackers to cause a denial of service (application crash) via a large TCP/IP port in the Windows registry key. | Assigned (20050906) | None (candidate not yet proposed) | View | |
14011 | CVE-2005-2805 | Candidate | forum_post.php in e107 0.6 allows remote attackers to post to non-existent forums by modifying the forum number. | Assigned (20050906) | None (candidate not yet proposed) | View | |
14012 | CVE-2005-2806 | Candidate | client.cpp in BNBT EasyTracker 7.7r3.2004.10.27 and earlier allows remote attackers to cause a denial of service (application hang) via an HTTP header containing only a ":" (colon), possibly leading to an integer signedness error due to a missing field name or value. | Assigned (20050906) | None (candidate not yet proposed) | View | |
13972 | CVE-2005-2766 | Candidate | Symantec AntiVirus Corporate Edition 9.0.1.x and 9.0.4.x, and possibly other versions, when obtaining updates from an internal LiveUpdate server, stores sensitive information in cleartext in the Log.Liveupdate log file, which allows attackers to obtain the username and password to the internal LiveUpdate server. | Assigned (20050902) | None (candidate not yet proposed) | View |
Page 18929 of 20943, showing 5 records out of 104715 total, starting on record 94641, ending on 94645