CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12785 | CVE-2005-1579 | Candidate | Apple QuickTime Player 7.0 on Mac OS X 10.4 allows remote attackers to obtain sensitive information via a .mov file with a Quartz Composer composition (.qtz) file that uses certain patches to read local information, then other patches to send the information to the attacker. | Assigned (20050514) | None (candidate not yet proposed) | View | |
12786 | CVE-2005-1580 | Candidate | users.ini.php in BoastMachine 3.0 does not properly restrict the types of files that can be uploaded, which allows remote attackers to execute arbitrary code. | Assigned (20050514) | None (candidate not yet proposed) | View | |
12787 | CVE-2005-1581 | Candidate | Cross-site scripting (XSS) vulnerability in Bug Report 1.0 allows remote attackers to inject arbitrary web script or HTML via various fields to bug_report.php, which are not filtered or quoted when processed by bug_list.php or admin/index.php. | Assigned (20050514) | None (candidate not yet proposed) | View | |
12788 | CVE-2005-1582 | Candidate | Cross-site scripting (XSS) vulnerability in index.php for 1Two News 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) nom, (2) email, (3) siteweb, or (4) commentaire variables. | Assigned (20050514) | None (candidate not yet proposed) | View | |
12789 | CVE-2005-1583 | Candidate | 1Two News 1.0 allows remote attackers to (1) delete images for new stories via a direct request to admin/delete.php or (2) upload arbitrary images via a direct request to admin/upload.php. | Assigned (20050514) | None (candidate not yet proposed) | View |
Page 19384 of 20943, showing 5 records out of 104715 total, starting on record 96916, ending on 96920