CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13741 | CVE-2005-2535 | Candidate | Buffer overflow in the Discovery Service in BrightStor ARCserve Backup 9.0 through 11.1 allows remote attackers to execute arbitrary commands via a large packet to TCP port 41523, a different vulnerability than CVE-2005-0260. | Assigned (20050810) | None (candidate not yet proposed) | View | |
13742 | CVE-2005-2536 | Candidate | pstotext before 1.8g does not properly use the "-dSAFER" option when calling Ghostscript to extract plain text from PostScript and PDF files, which allows remote attackers to execute arbitrary commands via a malicious PostScript file. | Assigned (20050810) | None (candidate not yet proposed) | View | |
13743 | CVE-2005-2537 | Candidate | FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via a direct request to structure.php. | Assigned (20050810) | None (candidate not yet proposed) | View | |
13744 | CVE-2005-2538 | Candidate | FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via (1) a null byte or (2) an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1 in the mod parameter. | Assigned (20050810) | None (candidate not yet proposed) | View | |
13745 | CVE-2005-2539 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in FlatNuke 2.5.5 and possibly earlier versions allow remote attackers to inject arbitrary web script or HTML via the (1) bodycolor, (2) backimage, (3) theme, or (4) logo parameter to structure.php, (5) admin, (6) admin_mail, or (7) back parameter to footer.php, or (8) the message body in a news post. | Assigned (20050810) | None (candidate not yet proposed) | View |
Page 1924 of 20943, showing 5 records out of 104715 total, starting on record 9616, ending on 9620