CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12785  CVE-2005-1579  Candidate  Apple QuickTime Player 7.0 on Mac OS X 10.4 allows remote attackers to obtain sensitive information via a .mov file with a Quartz Composer composition (.qtz) file that uses certain patches to read local information, then other patches to send the information to the attacker.  Assigned (20050514)  None (candidate not yet proposed)    View
12786  CVE-2005-1580  Candidate  users.ini.php in BoastMachine 3.0 does not properly restrict the types of files that can be uploaded, which allows remote attackers to execute arbitrary code.  Assigned (20050514)  None (candidate not yet proposed)    View
12787  CVE-2005-1581  Candidate  Cross-site scripting (XSS) vulnerability in Bug Report 1.0 allows remote attackers to inject arbitrary web script or HTML via various fields to bug_report.php, which are not filtered or quoted when processed by bug_list.php or admin/index.php.  Assigned (20050514)  None (candidate not yet proposed)    View
12788  CVE-2005-1582  Candidate  Cross-site scripting (XSS) vulnerability in index.php for 1Two News 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) nom, (2) email, (3) siteweb, or (4) commentaire variables.  Assigned (20050514)  None (candidate not yet proposed)    View
12789  CVE-2005-1583  Candidate  1Two News 1.0 allows remote attackers to (1) delete images for new stories via a direct request to admin/delete.php or (2) upload arbitrary images via a direct request to admin/upload.php.  Assigned (20050514)  None (candidate not yet proposed)    View

Page 19384 of 20943, showing 5 records out of 104715 total, starting on record 96916, ending on 96920

Actions