CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12048  CVE-2005-0842  Candidate  Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) _i or (2) _c parameter.  Assigned (20050324)  None (candidate not yet proposed)    View
12049  CVE-2005-0843  Candidate  CRLF injection vulnerability in search.php in Phorum 5.0.14a allows remote attackers to perform HTTP Response Splitting attacks via the body parameter, which is included in the resulting Location header.  Assigned (20050324)  None (candidate not yet proposed)    View
12050  CVE-2005-0844  Candidate  Nortel VPN client 5.01 stores the cleartext password in the memory of the Extranet.exe process, which could allow local users to obtain sensitive information.  Assigned (20050324)  None (candidate not yet proposed)    View
12051  CVE-2005-0845  Candidate  Directory traversal vulnerability in the Webmail interface in SurgeMail 2.2g3 allows remote authenticated users to write arbitrary files or directories via a .. (dot dot) in the attach_id parameter.  Assigned (20050324)  None (candidate not yet proposed)    View
12052  CVE-2005-0846  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the email auto-reply message in SurgeMail 2.2g3 allow remote attackers to inject arbitrary web script or HTML via the (1) message subject or (2) message header field.  Assigned (20050324)  None (candidate not yet proposed)    View

Page 19619 of 20943, showing 5 records out of 104715 total, starting on record 98091, ending on 98095

Actions