CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10690 | CVE-2004-2264 | Candidate | ** DISPUTED ** Format string bug in the open_altfile function in filename.c for GNU less 382, 381, and 358 might allow local users to cause a denial of service or possibly execute arbitrary code via format strings in the LESSOPEN environment variable. NOTE: since less is not setuid or setgid, then this is not a vulnerability unless there are plausible scenarios under which privilege boundaries could be crossed. | Assigned (20050719) | None (candidate not yet proposed) | View | |
13506 | CVE-2005-2300 | Candidate | Skype 1.1.0.20 and earlier allows local users to overwrite arbitrary files via a symlink attack on the skype_profile.jpg temporary file. | Assigned (20050719) | None (candidate not yet proposed) | View | |
10691 | CVE-2004-2265 | Candidate | UUDeview 0.5.20 and earlier handles temporary files insecurely during decoding, with unknown attack vectors and impact. | Assigned (20050719) | None (candidate not yet proposed) | View | |
13507 | CVE-2005-2301 | Candidate | PowerDNS before 2.9.18, when running with an LDAP backend, does not properly escape LDAP queries, which allows remote attackers to cause a denial of service (failure to answer ldap questions) and possibly conduct an LDAP injection attack. | Assigned (20050719) | None (candidate not yet proposed) | View | |
10692 | CVE-2004-2266 | Candidate | SQL injection vulnerability in Ansel 2.1 and earlier allows remote attackers to modify SQL statements via the image parameter. | Assigned (20050719) | None (candidate not yet proposed) | View |
Page 19077 of 20943, showing 5 records out of 104715 total, starting on record 95381, ending on 95385