CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12058  CVE-2005-0852  Candidate  Microsoft Windows XP SP1 allows local users to cause a denial of service (system crash) via an empty datagram to a raw IP over IP socket (IP protocol 4), as originally demonstrated using code in Python 2.3.  Assigned (20050324)  None (candidate not yet proposed)    View
12059  CVE-2005-0853  Candidate  betaparticle blog (bp blog) stores the database under the web root, which allows remote attackers to obtain sensitive information via a direct request to (1) dbBlogMX.mdb for versions before 3.0, or (2) Blog.mdb for versions 3.0 and later. NOTE: it was later reported that vector 2 also affects versions 6.0 through 9.0.  Assigned (20050324)  None (candidate not yet proposed)    View
12060  CVE-2005-0854  Candidate  betaparticle blog (bp blog), posisbly before version 4, allows remote attackers to bypass authentication and (1) upload files via a direct request to upload.asp or (2) delete files via a direct request to myFiles.asp.  Assigned (20050324)  None (candidate not yet proposed)    View
12061  CVE-2005-0855  Candidate  CoolForum 0.8.1 beta and earlier allows remote attackers to obtain sensitive path information via direct requests to (1) entete.php, (2) profile_accueil.php, (3) profile_mdp.php, (4) profile_notify.php, (5) profile_options.php, (6) profile_perso.php, (7) profile_pm.php, or (8) readannonce.php, which leaks the full pathname in a PHP error message.  Assigned (20050324)  None (candidate not yet proposed)    View
12062  CVE-2005-0856  Candidate  CoolForum 0.8.1 beta and earlier allows remote attackers to manipulate SQL commands via certain requests to (1) alert.php or (2) viewip.php, possibly due to a SQL injection vulnerability.  Assigned (20050324)  None (candidate not yet proposed)    View

Page 19621 of 20943, showing 5 records out of 104715 total, starting on record 98101, ending on 98105

Actions