CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12333  CVE-2005-1127  Candidate  Format string vulnerability in the log function in Net::Server 0.87 and earlier, as used in Postfix Greylisting Policy Server (Postgrey) 1.18 and earlier, and possibly other products, allows remote attackers to cause a denial of service (crash) via format string specifiers that are not properly handled before being sent to syslog, as demonstrated using sender addresses to Postgrey.  Assigned (20050416)  None (candidate not yet proposed)    View
12334  CVE-2005-1128  Candidate  Multiple SQL injection vulnerabilities in VHCS 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via certain inputs from HTTP POST queries.  Assigned (20050416)  None (candidate not yet proposed)    View
12335  CVE-2005-1129  Candidate  eGroupWare 1.0.6 and earlier, when an e-mail is composed with an attachment but not sent, will send that attachment in the next e-mail, which may cause sensitive information to be sent to the wrong recipient.  Assigned (20050416)  None (candidate not yet proposed)    View
12336  CVE-2005-1130  Candidate  Cross-site scripting (XSS) vulnerability in index.php in Pinnacle Cart allows remote attackers to inject arbitrary web script or HTML via the pg parameter.  Assigned (20050416)  None (candidate not yet proposed)    View
12337  CVE-2005-1131  Candidate  Unknown vulnerability in Veritas i3 Focalpoint Server 7.1 and earlier has unknown attack vectors and unknown but "critical" impact.  Assigned (20050416)  None (candidate not yet proposed)    View

Page 19553 of 20943, showing 5 records out of 104715 total, starting on record 97761, ending on 97765

Actions