CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13751  CVE-2005-2545  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in PHPOpenChat 3.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content parameter to profile.php and profile_misc.php, (3) the profile fields in userpage.php, (4) subject or (5) body in mail.php, or (8) disinvited_chatter or (7) invited_chatter parameter to invite.php.  Assigned (20050810)  None (candidate not yet proposed)    View
13752  CVE-2005-2546  Candidate  Arab Portal 2.0 allows remote attackers to obtain sensitive information via a long (1) username or (2) password, which reveals the path in an error message when the undefined "errmsg" function is called.  Assigned (20050810)  None (candidate not yet proposed)    View
13753  CVE-2005-2547  Candidate  security.c in hcid for BlueZ 2.16, 2.17, and 2.18 allows remote attackers to execute arbitrary commands via shell metacharacters in the Bluetooth device name when invoking the PIN helper.  Assigned (20050812)  None (candidate not yet proposed)    View
13754  CVE-2005-2548  Candidate  vlan_dev.c in the VLAN code for Linux kernel 2.6.8 allows remote attackers to cause a denial of service (kernel oops from null dereference) via certain UDP packets that lead to a function call with the wrong argument, as demonstrated using snmpwalk on snmpd.  Assigned (20050812)  None (candidate not yet proposed)    View
13755  CVE-2005-2549  Candidate  Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers.  Assigned (20050812)  None (candidate not yet proposed)    View

Page 1926 of 20943, showing 5 records out of 104715 total, starting on record 9626, ending on 9630

Actions