CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12736  CVE-2005-1530  Candidate  Sophos Anti-Virus 5.0.1, with "Scan inside archive files" enabled, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a Bzip2 archive with a large "Extra field length" value.  Assigned (20050512)  None (candidate not yet proposed)    View
12737  CVE-2005-1531  Candidate  Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) "a nested variant."  Assigned (20050512)  None (candidate not yet proposed)    View
12738  CVE-2005-1532  Candidate  Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.  Assigned (20050512)  None (candidate not yet proposed)    View
12684  CVE-2005-1478  Candidate  Format string vulnerability in dSMTP (dsmtp.exe) in DMail 3.1a allows remote attackers to execute arbitrary code via format string specifiers in the xtellmail command.  Assigned (20050511)  None (candidate not yet proposed)    View
12685  CVE-2005-1479  Candidate  SQL injection vulnerability in jgs_portal.php in JGS-Portal 3.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20050511)  None (candidate not yet proposed)    View

Page 19388 of 20943, showing 5 records out of 104715 total, starting on record 96936, ending on 96940

Actions