CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12736 | CVE-2005-1530 | Candidate | Sophos Anti-Virus 5.0.1, with "Scan inside archive files" enabled, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a Bzip2 archive with a large "Extra field length" value. | Assigned (20050512) | None (candidate not yet proposed) | View | |
12737 | CVE-2005-1531 | Candidate | Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) "a nested variant." | Assigned (20050512) | None (candidate not yet proposed) | View | |
12738 | CVE-2005-1532 | Candidate | Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160. | Assigned (20050512) | None (candidate not yet proposed) | View | |
12684 | CVE-2005-1478 | Candidate | Format string vulnerability in dSMTP (dsmtp.exe) in DMail 3.1a allows remote attackers to execute arbitrary code via format string specifiers in the xtellmail command. | Assigned (20050511) | None (candidate not yet proposed) | View | |
12685 | CVE-2005-1479 | Candidate | SQL injection vulnerability in jgs_portal.php in JGS-Portal 3.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | Assigned (20050511) | None (candidate not yet proposed) | View |
Page 19388 of 20943, showing 5 records out of 104715 total, starting on record 96936, ending on 96940