CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12825  CVE-2005-1619  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in (1) start_page.css.php3 (aka start-page.css.php3) or (2) style.css.php3 in PHPMyChat 0.14.5 allow remote attackers to inject arbitrary web script or HTML commands via the FontName parameter. NOTE: it was later reported that 0.14.5 is also affected.  Assigned (20050516)  None (candidate not yet proposed)    View
12826  CVE-2005-1620  Candidate  Cross-site scripting (XSS) vulnerability in Skull-Splitter Guestbook 1.0, 2.0 and 2.2 allows remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message.  Assigned (20050516)  None (candidate not yet proposed)    View
12827  CVE-2005-1621  Candidate  Directory traversal vulnerability in the pnModFunc function in pnMod.php for PostNuke 0.750 through 0.760rc4 allows remote attackers to read arbitrary files via a .. (dot dot) in the func parameter to index.php.  Assigned (20050516)  None (candidate not yet proposed)    View
12828  CVE-2005-1622  Candidate  Cross-site scripting (XSS) vulnerability in productsByCategory.asp in MetaCart e-Shop allows remote attackers to inject arbitrary web script or HTML via the strCatalog_NAME parameter.  Assigned (20050516)  None (candidate not yet proposed)    View
12795  CVE-2005-1589  Candidate  The pkt_ioctl function in the pktcdvd block device ioctl handler (pktcdvd.c) in Linux kernel 2.6.12-rc4 and earlier calls the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space and allows local users to cause a denial of service and possibly execute arbitrary code, a similar vulnerability to CVE-2005-1264.  Assigned (20050516)  None (candidate not yet proposed)    View

Page 19373 of 20943, showing 5 records out of 104715 total, starting on record 96861, ending on 96865

Actions