CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13751 | CVE-2005-2545 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in PHPOpenChat 3.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content parameter to profile.php and profile_misc.php, (3) the profile fields in userpage.php, (4) subject or (5) body in mail.php, or (8) disinvited_chatter or (7) invited_chatter parameter to invite.php. | Assigned (20050810) | None (candidate not yet proposed) | View | |
13752 | CVE-2005-2546 | Candidate | Arab Portal 2.0 allows remote attackers to obtain sensitive information via a long (1) username or (2) password, which reveals the path in an error message when the undefined "errmsg" function is called. | Assigned (20050810) | None (candidate not yet proposed) | View | |
13753 | CVE-2005-2547 | Candidate | security.c in hcid for BlueZ 2.16, 2.17, and 2.18 allows remote attackers to execute arbitrary commands via shell metacharacters in the Bluetooth device name when invoking the PIN helper. | Assigned (20050812) | None (candidate not yet proposed) | View | |
13754 | CVE-2005-2548 | Candidate | vlan_dev.c in the VLAN code for Linux kernel 2.6.8 allows remote attackers to cause a denial of service (kernel oops from null dereference) via certain UDP packets that lead to a function call with the wrong argument, as demonstrated using snmpwalk on snmpd. | Assigned (20050812) | None (candidate not yet proposed) | View | |
13755 | CVE-2005-2549 | Candidate | Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers. | Assigned (20050812) | None (candidate not yet proposed) | View |
Page 1926 of 20943, showing 5 records out of 104715 total, starting on record 9626, ending on 9630