CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12171  CVE-2005-0965  Candidate  The gaim_markup_strip_html function in Gaim 1.2.0, and possibly earlier versions, allows remote attackers to cause a denial of service (application crash) via a string that contains malformed HTML, which causes an out-of-bounds read.  Assigned (20050404)  None (candidate not yet proposed)    View
12172  CVE-2005-0966  Candidate  The IRC protocol plugin in Gaim 1.2.0, and possibly earlier versions, allows (1) remote attackers to inject arbitrary Gaim markup via irc_msg_kick, irc_msg_mode, irc_msg_part, irc_msg_quit, (2) remote attackers to inject arbitrary Pango markup and pop up empty dialog boxes via irc_msg_invite, or (3) malicious IRC servers to cause a denial of service (application crash) by injecting certain Pango markup into irc_msg_badmode, irc_msg_banned, irc_msg_unknown, irc_msg_nochan functions.  Assigned (20050404)  None (candidate not yet proposed)    View
12149  CVE-2005-0943  Candidate  Cisco VPN 3000 series Concentrator running firmware 4.1.7.A and earlier allows remote attackers to cause a denial of service (device reload or drop user connection) via a crafted HTTPS packet.  Assigned (20050403)  None (candidate not yet proposed)    View
12150  CVE-2005-0944  Candidate  Unknown vulnerability in Microsoft Jet DB engine (msjet40.dll) 4.00.8618.0, related to insufficient data validation, allows remote attackers to execute arbitrary code via a crafted mdb file.  Assigned (20050403)  None (candidate not yet proposed)    View
12151  CVE-2005-0945  Candidate  Cross-site scripting (XSS) vulnerability in ACS Blog 1.1.1 allows remote attackers to inject arbitrary web script or HTML via onmouseover or onload events in (1) img, (2) link, or (3) mail tags.  Assigned (20050403)  None (candidate not yet proposed)    View

Page 19586 of 20943, showing 5 records out of 104715 total, starting on record 97926, ending on 97930

Actions