CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14009  CVE-2005-2803  Candidate  Cross-site scripting (XSS) vulnerability in Hiki 0.8.1 to 0.8.2 allows remote attackers to inject arbitrary web script or HTML via a page name in a Login link, a different vulnerability than CVE-2005-2336.  Assigned (20050906)  None (candidate not yet proposed)    View
14010  CVE-2005-2804  Candidate  Integer overflow in the registry parsing code in GroupWise 6.5.3, and possibly earlier version, allows remote attackers to cause a denial of service (application crash) via a large TCP/IP port in the Windows registry key.  Assigned (20050906)  None (candidate not yet proposed)    View
14011  CVE-2005-2805  Candidate  forum_post.php in e107 0.6 allows remote attackers to post to non-existent forums by modifying the forum number.  Assigned (20050906)  None (candidate not yet proposed)    View
14012  CVE-2005-2806  Candidate  client.cpp in BNBT EasyTracker 7.7r3.2004.10.27 and earlier allows remote attackers to cause a denial of service (application hang) via an HTTP header containing only a ":" (colon), possibly leading to an integer signedness error due to a missing field name or value.  Assigned (20050906)  None (candidate not yet proposed)    View
13972  CVE-2005-2766  Candidate  Symantec AntiVirus Corporate Edition 9.0.1.x and 9.0.4.x, and possibly other versions, when obtaining updates from an internal LiveUpdate server, stores sensitive information in cleartext in the Log.Liveupdate log file, which allows attackers to obtain the username and password to the internal LiveUpdate server.  Assigned (20050902)  None (candidate not yet proposed)    View

Page 18929 of 20943, showing 5 records out of 104715 total, starting on record 94641, ending on 94645

Actions