CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12348 | CVE-2005-1142 | Candidate | Heap-based buffer overflow in the readpgm function in pnm.c for GOCR 0.40, when it is not using netpbm, allows remote attackers to execute arbitrary code via a P3 format PNM file with more data than implied by its width and height values. | Assigned (20050416) | None (candidate not yet proposed) | View | |
12349 | CVE-2005-1143 | Candidate | Cross-site scripting (XSS) vulnerability in index.php in EasyPHPCalendar before 6.2.8 allows remote attackers to inject arbitrary web script or HTML via the yr parameter. | Assigned (20050416) | None (candidate not yet proposed) | View | |
12350 | CVE-2005-1144 | Candidate | popup.php in EasyPHPCalendar before 6.2.8 allows remote attackers to obtain sensitive information via an invalid ev parameter, which reveals the full pathname of the web server in a PHP error message. | Assigned (20050416) | None (candidate not yet proposed) | View | |
12351 | CVE-2005-1145 | Candidate | ** DISPUTED ** NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in calendar.pl in CalendarScript 3.20 allows remote attackers to inject arbitrary web script or HTML via the template parameter, a different vulnerability than CVE-2005-1146. | Assigned (20050416) | None (candidate not yet proposed) | View | |
12352 | CVE-2005-1146 | Candidate | ** DISPUTED ** NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in the login command in calendar.pl in CalendarScript 3.21 allows remote attackers to inject arbitrary web script or HTML via the username parameter, a different vulnerability than CVE-2005-1145. | Assigned (20050416) | None (candidate not yet proposed) | View |
Page 19556 of 20943, showing 5 records out of 104715 total, starting on record 97776, ending on 97780