CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12171 | CVE-2005-0965 | Candidate | The gaim_markup_strip_html function in Gaim 1.2.0, and possibly earlier versions, allows remote attackers to cause a denial of service (application crash) via a string that contains malformed HTML, which causes an out-of-bounds read. | Assigned (20050404) | None (candidate not yet proposed) | View | |
12172 | CVE-2005-0966 | Candidate | The IRC protocol plugin in Gaim 1.2.0, and possibly earlier versions, allows (1) remote attackers to inject arbitrary Gaim markup via irc_msg_kick, irc_msg_mode, irc_msg_part, irc_msg_quit, (2) remote attackers to inject arbitrary Pango markup and pop up empty dialog boxes via irc_msg_invite, or (3) malicious IRC servers to cause a denial of service (application crash) by injecting certain Pango markup into irc_msg_badmode, irc_msg_banned, irc_msg_unknown, irc_msg_nochan functions. | Assigned (20050404) | None (candidate not yet proposed) | View | |
12149 | CVE-2005-0943 | Candidate | Cisco VPN 3000 series Concentrator running firmware 4.1.7.A and earlier allows remote attackers to cause a denial of service (device reload or drop user connection) via a crafted HTTPS packet. | Assigned (20050403) | None (candidate not yet proposed) | View | |
12150 | CVE-2005-0944 | Candidate | Unknown vulnerability in Microsoft Jet DB engine (msjet40.dll) 4.00.8618.0, related to insufficient data validation, allows remote attackers to execute arbitrary code via a crafted mdb file. | Assigned (20050403) | None (candidate not yet proposed) | View | |
12151 | CVE-2005-0945 | Candidate | Cross-site scripting (XSS) vulnerability in ACS Blog 1.1.1 allows remote attackers to inject arbitrary web script or HTML via onmouseover or onload events in (1) img, (2) link, or (3) mail tags. | Assigned (20050403) | None (candidate not yet proposed) | View |
Page 19586 of 20943, showing 5 records out of 104715 total, starting on record 97926, ending on 97930