CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13845  CVE-2005-2639  Candidate  Buffer overflow in Chris Moneymaker"s World Poker Championship 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long nickname.  Assigned (20050820)  None (candidate not yet proposed)    View
13846  CVE-2005-2640  Candidate  Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to enumerate valid usernames via an IKE Aggressive Mode packet, which generates a response if the username is valid but does not respond when the username is invalid.  Assigned (20050820)  None (candidate not yet proposed)    View
10861  CVE-2004-2435  Candidate  Cross-site scripting (XSS) vulnerability in PeopleSoft Human Resources Management System (HRMS) 7.0, when "web enabled" using HTML Access, allows remote attackers to inject arbitrary web script or HTML via unspecified (1) debugging or (2) utility scripts.  Assigned (20050820)  None (candidate not yet proposed)    View
10862  CVE-2004-2436  Candidate  Computer Associates Unicenter Common Services 3.0 and earlier stores the database "SA" password in cleartext in the TndAddNspTmp.bat file, which could allow local users to gain privileges.  Assigned (20050820)  None (candidate not yet proposed)    View
10863  CVE-2004-2437  Candidate  SQL injection vulnerability in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the rowstart parameter to (1) index.php or (2) members.php, or (3) the comment_id parameter to comments.php.  Assigned (20050820)  None (candidate not yet proposed)    View

Page 18964 of 20943, showing 5 records out of 104715 total, starting on record 94816, ending on 94820

Actions