CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13138  CVE-2005-1932  Candidate  Lpanel 1.59 and earlier, and other versions before 1.597, allows remote authenticated users to modify certain critical variables and (1) modify DNS settings for arbitrary domains via the domain parameter to diagnose.php, (2) close, open, or respond to arbitrary support tickets via the close, open, or pid parameter to view_ticket.php, (3) obtain sensitive information on arbitrary invoices via the inv parameter to viewreceipt.php, or (4) modify domain information for arbitrary domains via the editdomain parameter to domains.php.  Assigned (20050609)  None (candidate not yet proposed)    View
13139  CVE-2005-1933  Candidate  Dashboard in Apple Mac OS X Tiger 10.4 allows attackers to execute arbitrary commands by overriding the behavior of system widgets via a user widget with the same bundle identifier (CFBundleIdentifier), a different vulnerability than CVE-2005-1474.  Assigned (20050609)  None (candidate not yet proposed)    View
13140  CVE-2005-1934  Candidate  Gaim before 1.3.1 allows remote attackers to cause a denial of service (crash) via a malformed MSN message that leads to a memory allocation of a large size, possibly due to an integer signedness error.  Assigned (20050609)  None (candidate not yet proposed)    View
13141  CVE-2005-1935  Candidate  Heap-based buffer overflow in the BERDecBitString function in Microsoft ASN.1 library (MSASN1.DLL) allows remote attackers to execute arbitrary code via nested constructed bit strings, which leads to a realloc of a non-null pointer and causes the function to overwrite previously freed memory, as demonstrated using a SPNEGO token with a constructed bit string during HTTP authentication, and a different vulnerability than CVE-2003-0818. NOTE: the researcher has claimed that MS:MS04-007 fixes this issue.  Assigned (20050609)  None (candidate not yet proposed)    View
13070  CVE-2005-1864  Candidate  PHP remote file inclusion vulnerability in cal_admintop.php in Calendarix Advanced 1.5 allows remote attackers to execute arbitrary PHP code via the calpath parameter.  Assigned (20050608)  None (candidate not yet proposed)    View

Page 19288 of 20943, showing 5 records out of 104715 total, starting on record 96436, ending on 96440

Actions