CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10690  CVE-2004-2264  Candidate  ** DISPUTED ** Format string bug in the open_altfile function in filename.c for GNU less 382, 381, and 358 might allow local users to cause a denial of service or possibly execute arbitrary code via format strings in the LESSOPEN environment variable. NOTE: since less is not setuid or setgid, then this is not a vulnerability unless there are plausible scenarios under which privilege boundaries could be crossed.  Assigned (20050719)  None (candidate not yet proposed)    View
13506  CVE-2005-2300  Candidate  Skype 1.1.0.20 and earlier allows local users to overwrite arbitrary files via a symlink attack on the skype_profile.jpg temporary file.  Assigned (20050719)  None (candidate not yet proposed)    View
10691  CVE-2004-2265  Candidate  UUDeview 0.5.20 and earlier handles temporary files insecurely during decoding, with unknown attack vectors and impact.  Assigned (20050719)  None (candidate not yet proposed)    View
13507  CVE-2005-2301  Candidate  PowerDNS before 2.9.18, when running with an LDAP backend, does not properly escape LDAP queries, which allows remote attackers to cause a denial of service (failure to answer ldap questions) and possibly conduct an LDAP injection attack.  Assigned (20050719)  None (candidate not yet proposed)    View
10692  CVE-2004-2266  Candidate  SQL injection vulnerability in Ansel 2.1 and earlier allows remote attackers to modify SQL statements via the image parameter.  Assigned (20050719)  None (candidate not yet proposed)    View

Page 19077 of 20943, showing 5 records out of 104715 total, starting on record 95381, ending on 95385

Actions