CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12701  CVE-2005-1495  Candidate  Oracle Database 9i and 10g disables Fine Grained Audit (FGA) after the SYS user executes a SELECT statement on an FGA object, which makes it easier for attackers to escape detection.  Assigned (20050511)  None (candidate not yet proposed)    View
12702  CVE-2005-1496  Candidate  The DBMS_Scheduler in Oracle 10g allows remote attackers with CREATE JOB privileges to gain additional privileges by changing SESSION_USER to the SYS user.  Assigned (20050511)  None (candidate not yet proposed)    View
12703  CVE-2005-1497  Candidate  index.php in myBloggie 2.1.1 allows remote attackers to obtain sensitive information via an invalid post_id parameter, which reveals the path in an error message.  Assigned (20050511)  None (candidate not yet proposed)    View
12704  CVE-2005-1498  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in myBloggie 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) year parameter in viewmode.php, or the (2) cat_id, (3) month_no, or (4) post_id parameter in index.php, which are not properly sanitized before they are displayed in an error message. NOTE: issues 2, 3, and 4 may be due to a problem in associated products rather than myBloggie itself.  Assigned (20050511)  None (candidate not yet proposed)    View
12705  CVE-2005-1499  Candidate  delcomment.php in myBloggie 2.1.1 allows remote attackers to delete arbitrary comments by modifying the comment_id parameter.  Assigned (20050511)  None (candidate not yet proposed)    View

Page 19392 of 20943, showing 5 records out of 104715 total, starting on record 96956, ending on 96960

Actions