CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10560  CVE-2004-2134  Candidate  Oracle toplink mapping workBench uses a weak encryption algorithm for passwords, which allows local users to decrypt the passwords.  Assigned (20050527)  None (candidate not yet proposed)    View
8039  CVE-2003-1215  Candidate  SQL injection vulnerability in groupcp.php for phpBB 2.0.6 and earlier allows group moderators to perform unauthorized activities via the sql_in parameter.  Assigned (20050527)  None (candidate not yet proposed)    View
8040  CVE-2003-1216  Candidate  SQL injection vulnerability in search.php for phpBB 2.0.6 and earlier allows remote attackers to execute arbitrary SQL and gain privileges via the search_id parameter.  Assigned (20050527)  None (candidate not yet proposed)    View
12958  CVE-2005-1752  Candidate  viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file_name parameter.  Assigned (20050526)  None (candidate not yet proposed)    View
12959  CVE-2005-1753  Candidate  ** DISPUTED ** ReadMessage.jsp in JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to view other users" e-mail attachments via a direct request to /mailboxesdir/username@domainname. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products."  Assigned (20050526)  None (candidate not yet proposed)    View

Page 19333 of 20943, showing 5 records out of 104715 total, starting on record 96661, ending on 96665

Actions