CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12391  CVE-2005-1185  Candidate  Unquoted Windows search path vulnerability in Musicmatch Jukebox 10.00.2047 and earlier allows local users to gain privileges via a malicious C:program.exe file, which is run by MMFWLaunch.exe when it attempts to execute launch.exe.  Assigned (20050419)  None (candidate not yet proposed)    View
12392  CVE-2005-1186  Candidate  Musicmatch Jukebox 10.00.2047 and earlier adds the musicmatch.com domain to the Trusted Sites zone in Internet Explorer, which allows systems in the domain to conduct unauthorized activities, as demonstrated using cross-site scripting (XSS) attacks.  Assigned (20050419)  None (candidate not yet proposed)    View
12393  CVE-2005-1187  Candidate  Heap-based buffer overflow in WinHex 12.05 SR-14, and possibly other versions, may allow attackers to execute arbitrary code via a long file name argument. NOTE: since this overflow is in the command line of an unprivileged program, it is highly likely that this is not a vulnerability.  Assigned (20050419)  None (candidate not yet proposed)    View
12394  CVE-2005-1188  Candidate  Cross-site scripting (XSS) vulnerability in comersus_searchItem.asp in Comersus 3.90 to 4.51 allows remote attackers to inject arbitrary web script or HTML via the curPage parameter.  Assigned (20050419)  None (candidate not yet proposed)    View
12395  CVE-2005-1189  Candidate  Cross-site scripting (XSS) vulnerability in WebcamXP PRO v2.16.468 and earlier allows remote attackers to inject arbitrary web script or HTML via the chat name, as demonstrated by using an IFRAME to redirect users to other sites.  Assigned (20050419)  None (candidate not yet proposed)    View

Page 19543 of 20943, showing 5 records out of 104715 total, starting on record 97711, ending on 97715

Actions