CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13291  CVE-2005-2085  Candidate  Buffer overflow in Inframail Advantage Server Edition 6.0 through 6.7 allows remote attackers to cause a denial of service (process crash) via a long (1) SMTP FROM field or possibly (2) FTP NLST command.  Assigned (20050630)  None (candidate not yet proposed)    View
13292  CVE-2005-2086  Candidate  PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute arbitrary PHP code.  Assigned (20050630)  None (candidate not yet proposed)    View
13293  CVE-2005-2087  Candidate  Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, as demonstrated using the JVIEW Profiler (Javaprxy.dll). NOTE: the researcher says that the vendor could not reproduce this problem.  Assigned (20050630)  None (candidate not yet proposed)    View
13294  CVE-2005-2088  Candidate  The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."  Assigned (20050630)  None (candidate not yet proposed)    View
13295  CVE-2005-2089  Candidate  Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes IIS to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."  Assigned (20050630)  None (candidate not yet proposed)    View

Page 19185 of 20943, showing 5 records out of 104715 total, starting on record 95921, ending on 95925

Actions