CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12167  CVE-2005-0961  Candidate  Cross-site scripting (XSS) vulnerability in Horde 3.0.4 before 3.0.4-RC2 allows remote attackers to inject arbitrary web script or HTML via the parent frame title.  Assigned (20050403)  None (candidate not yet proposed)    View
12168  CVE-2005-0962  Candidate  SQL injection vulnerability in index.php for Lighthouse Squirrelcart allows remote attackers to execute arbitrary SQL commands via the (1) crn parameter in a show action or (2) rn parameter in a show_detail action.  Assigned (20050403)  None (candidate not yet proposed)    View
12169  CVE-2005-0963  Candidate  An error in the Toshiba ACPI BIOS 1.6 causes the BIOS to only examine the first slot in the Master Boot Record (MBR) table for an active partition, which prevents the system from booting even though the MBR is not malformed. NOTE: it has been debated as to whether or not this issue poses a security vulnerability, since administrative privileges would be required, and other DoS attacks are possible with such privileges.  Assigned (20050403)  None (candidate not yet proposed)    View
12170  CVE-2005-0964  Candidate  Unknown vulnerability in Kerio Personal Firewall 4.1.2 and earlier allows local users to bypass firewall rules via a malicious process that impersonates a legitimate process that has fewer restrictions.  Assigned (20050403)  None (candidate not yet proposed)    View
12147  CVE-2005-0941  Candidate  The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but process memory using 32 bit values, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a DOC document with certain length values, which leads to a heap-based buffer overflow.  Assigned (20050331)  None (candidate not yet proposed)    View

Page 19590 of 20943, showing 5 records out of 104715 total, starting on record 97946, ending on 97950

Actions