CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12001  CVE-2005-0795  Candidate  HolaCMS 1.4.9 does not restrict file access to the holaDB/votes directory, which allows remote attackers to overwrite arbitrary files via a modified vote_filename parameter.  Assigned (20050320)  None (candidate not yet proposed)    View
12002  CVE-2005-0796  Candidate  Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/votes" followed by a .. (dot dot) in the vote_filename parameter, which bypasses the check by HolaCMS to ensure that the file is in the holaDB/votes directory.  Assigned (20050320)  None (candidate not yet proposed)    View
12003  CVE-2005-0797  Candidate  Novell iChain Mini FTP Server 2.3 displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks.  Assigned (20050320)  None (candidate not yet proposed)    View
12004  CVE-2005-0798  Candidate  Novell iChain Mini FTP Server 2.3, and possibly earlier versions, does not limit the number of incorrect logins, which makes it easier for remote attackers to conduct brute force login attacks.  Assigned (20050320)  None (candidate not yet proposed)    View
12005  CVE-2005-0799  Candidate  MySQL 4.1.9, and possibly earlier versions, allows remote attackers with certain privileges to cause a denial of service (application crash) via a use command followed by an MS-DOS device name such as (1) LPT1 or (2) PRN.  Assigned (20050320)  None (candidate not yet proposed)    View

Page 19634 of 20943, showing 5 records out of 104715 total, starting on record 98166, ending on 98170

Actions