CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13503 | CVE-2005-2297 | Candidate | Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary code via a large javascript parameter. | Assigned (20050719) | None (candidate not yet proposed) | View | |
10688 | CVE-2004-2262 | Candidate | ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php. | Assigned (20050719) | None (candidate not yet proposed) | View | |
13504 | CVE-2005-2298 | Candidate | BitDefender Engine 1.6.1 and earlier does not properly scan all attachments, which allows remote attackers to bypass virus scanning via begin and end commands in the body of the e-mail, which BitDefender treats as a uuencoded attachment and stops scanning afterwards. | Assigned (20050719) | None (candidate not yet proposed) | View | |
10689 | CVE-2004-2263 | Candidate | SQL injection vulnerability in the valid function in fr_left.php in PlaySMS 0.7 and earlier allows remote attackers to modify SQL statements via the vc2 cookie. | Assigned (20050719) | None (candidate not yet proposed) | View | |
13505 | CVE-2005-2299 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Simple Message Board Version 2.0 Beta 1 allow remote attackers to inject arbitrary web script or HTML via the (1) FID parameter to forum.cfm, (2) UID parameter to user.cfm, (3) TID parameter to thread.cfm, or (4) PostDate parameter to search.cfm. | Assigned (20050719) | None (candidate not yet proposed) | View |
Page 19076 of 20943, showing 5 records out of 104715 total, starting on record 95376, ending on 95380