CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12825 | CVE-2005-1619 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in (1) start_page.css.php3 (aka start-page.css.php3) or (2) style.css.php3 in PHPMyChat 0.14.5 allow remote attackers to inject arbitrary web script or HTML commands via the FontName parameter. NOTE: it was later reported that 0.14.5 is also affected. | Assigned (20050516) | None (candidate not yet proposed) | View | |
12826 | CVE-2005-1620 | Candidate | Cross-site scripting (XSS) vulnerability in Skull-Splitter Guestbook 1.0, 2.0 and 2.2 allows remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message. | Assigned (20050516) | None (candidate not yet proposed) | View | |
12827 | CVE-2005-1621 | Candidate | Directory traversal vulnerability in the pnModFunc function in pnMod.php for PostNuke 0.750 through 0.760rc4 allows remote attackers to read arbitrary files via a .. (dot dot) in the func parameter to index.php. | Assigned (20050516) | None (candidate not yet proposed) | View | |
12828 | CVE-2005-1622 | Candidate | Cross-site scripting (XSS) vulnerability in productsByCategory.asp in MetaCart e-Shop allows remote attackers to inject arbitrary web script or HTML via the strCatalog_NAME parameter. | Assigned (20050516) | None (candidate not yet proposed) | View | |
12795 | CVE-2005-1589 | Candidate | The pkt_ioctl function in the pktcdvd block device ioctl handler (pktcdvd.c) in Linux kernel 2.6.12-rc4 and earlier calls the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space and allows local users to cause a denial of service and possibly execute arbitrary code, a similar vulnerability to CVE-2005-1264. | Assigned (20050516) | None (candidate not yet proposed) | View |
Page 19373 of 20943, showing 5 records out of 104715 total, starting on record 96861, ending on 96865