CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13659  CVE-2005-2453  Candidate  Cross-site scripting (XSS) vulnerability in NetworkActiv Web Server 1.0, 2.0.0.6, 3.0.1.1, and 3.5.13, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the query string.  Assigned (20050804)  None (candidate not yet proposed)    View
13660  CVE-2005-2454  Candidate  IBM Lotus Notes 6.5.4 and 6.5.5, and 7.0.0 and 7.0.1, uses insecure default permissions (Everyone/Full Control) for the "Notes" folder and all children, which allows local users to gain privileges and modify, add, or delete files in that folder.  Assigned (20050804)  None (candidate not yet proposed)    View
13661  CVE-2005-2455  Candidate  Greasemonkey before 0.3.5 allows remote web servers to (1) read arbitrary files via a GET request to a file:// URL in the GM_xmlhttpRequest API function, (2) list installed scripts using GM_scripts, or obtain sensitive information via (3) GM_setValue and GM_getValue.  Assigned (20050804)  None (candidate not yet proposed)    View
13662  CVE-2005-2456  Candidate  Array index overflow in the xfrm_sk_policy_insert function in xfrm_user.c in Linux kernel 2.6 allows local users to cause a denial of service (oops or deadlock) and possibly execute arbitrary code via a p->dir value that is larger than XFRM_POLICY_OUT, which is used as an index in the sock->sk_policy array.  Assigned (20050804)  None (candidate not yet proposed)    View
13663  CVE-2005-2457  Candidate  The driver for compressed ISO file systems (zisofs) in the Linux kernel before 2.6.12.5 allows local users and remote attackers to cause a denial of service (kernel crash) via a crafted compressed ISO file system.  Assigned (20050804)  None (candidate not yet proposed)    View

Page 1895 of 20943, showing 5 records out of 104715 total, starting on record 9471, ending on 9475

Actions