CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12308  CVE-2005-1102  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in template-functions-post.php in WordPress 1.5 and earlier allow remote attackers to execute arbitrary commands via the (1) content or (2) title of the post.  Assigned (20050413)  None (candidate not yet proposed)    View
12309  CVE-2005-1103  Candidate  Sygate Security Agent (SSA) in Sygate Secure Enterprise 3.5 through 4.1 does not prevent the security policy from being updated by unprivileged users, which allows local users to modify the policy by exporting the policy file, changing it, and importing it back into SSA.  Assigned (20050413)  None (candidate not yet proposed)    View
12310  CVE-2005-1104  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Centra 7 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) first name, or (3) last name fields.  Assigned (20050413)  None (candidate not yet proposed)    View
12311  CVE-2005-1105  Candidate  Directory traversal vulnerability in the MimeBodyPart.getFileName method in JavaMail 1.3.2 allows remote attackers to write arbitrary files via a .. (dot dot) in the filename in the Content-Disposition header.  Assigned (20050413)  None (candidate not yet proposed)    View
12312  CVE-2005-1106  Candidate  PictureViewer in QuickTime for Windows 6.5.2 allows remote attackers to cause a denial of service (application crash) via a GIF image with the maximum depth start value, possibly triggering an integer overflow.  Assigned (20050413)  None (candidate not yet proposed)    View

Page 19562 of 20943, showing 5 records out of 104715 total, starting on record 97806, ending on 97810

Actions