CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10682  CVE-2004-2256  Candidate  Directory traversal vulnerability in phpMyFAQ 1.4.0 alpha allows remote attackers to read arbitrary files, and possibly execute local PHP files, via .. sequences in the lang (language) variable.  Assigned (20050717)  None (candidate not yet proposed)    View
13498  CVE-2005-2292  Candidate  Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 stores cleartext passwords in (1) IDEConnections.xml, (2) XSQLConfig.xml and (3) settings.xml, which allows local users to obtain sensitive information.  Assigned (20050717)  None (candidate not yet proposed)    View
10683  CVE-2004-2257  Candidate  phpMyFAQ 1.4.0 allows remote attackers to access the Image Manager to upload or delete images without authorization via a direct request.  Assigned (20050717)  None (candidate not yet proposed)    View
13499  CVE-2005-2293  Candidate  Oracle Formsbuilder 9.0.4 stores database usernames and passwords in a temporary file, which is not deleted after it is used, which allows local users to obtain sensitive information.  Assigned (20050717)  None (candidate not yet proposed)    View
13500  CVE-2005-2294  Candidate  Oracle Forms 4.5, 6.0, 6i, and 9i on Unix, when a large number of records are retrieved by an Oracle form, stores a copy of the database tables in a world-readable temporary file, which allows local users to gain sensitive information such as credit card numbers.  Assigned (20050717)  None (candidate not yet proposed)    View

Page 19098 of 20943, showing 5 records out of 104715 total, starting on record 95486, ending on 95490

Actions