CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12348  CVE-2005-1142  Candidate  Heap-based buffer overflow in the readpgm function in pnm.c for GOCR 0.40, when it is not using netpbm, allows remote attackers to execute arbitrary code via a P3 format PNM file with more data than implied by its width and height values.  Assigned (20050416)  None (candidate not yet proposed)    View
12349  CVE-2005-1143  Candidate  Cross-site scripting (XSS) vulnerability in index.php in EasyPHPCalendar before 6.2.8 allows remote attackers to inject arbitrary web script or HTML via the yr parameter.  Assigned (20050416)  None (candidate not yet proposed)    View
12350  CVE-2005-1144  Candidate  popup.php in EasyPHPCalendar before 6.2.8 allows remote attackers to obtain sensitive information via an invalid ev parameter, which reveals the full pathname of the web server in a PHP error message.  Assigned (20050416)  None (candidate not yet proposed)    View
12351  CVE-2005-1145  Candidate  ** DISPUTED ** NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in calendar.pl in CalendarScript 3.20 allows remote attackers to inject arbitrary web script or HTML via the template parameter, a different vulnerability than CVE-2005-1146.  Assigned (20050416)  None (candidate not yet proposed)    View
12352  CVE-2005-1146  Candidate  ** DISPUTED ** NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in the login command in calendar.pl in CalendarScript 3.21 allows remote attackers to inject arbitrary web script or HTML via the username parameter, a different vulnerability than CVE-2005-1145.  Assigned (20050416)  None (candidate not yet proposed)    View

Page 19556 of 20943, showing 5 records out of 104715 total, starting on record 97776, ending on 97780

Actions