CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12011  CVE-2005-0805  Candidate  SQL injection vulnerability in index.php in Subdreamer Light, when magic_quotes_gpc is enabled, allows remote attackers to execute arbitrary SQL commands via certain parameters that are used as global variables, as demonstrated using the imageid parameter, which is not properly handled by imagegallery.php.  Assigned (20050320)  None (candidate not yet proposed)    View
12012  CVE-2005-0806  Candidate  Evolution 2.0.3 allows remote attackers to cause a denial of service (application crash or hang) via crafted messages, possibly involving charsets in attachment filenames.  Assigned (20050320)  None (candidate not yet proposed)    View
12013  CVE-2005-0807  Candidate  Multiple buffer overflows in Cain & Abel before 2.67 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via (1) an IKE packet with a large ID field that is not properly handled by the PSK sniffer filter, (2) the HTTP sniffer filter, or the (3) POP3, (4) SMTP, (5) IMAP, (6) NNTP, or (7) TDS sniffer filters.  Assigned (20050320)  None (candidate not yet proposed)    View
12014  CVE-2005-0808  Candidate  Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007.  Assigned (20050320)  None (candidate not yet proposed)    View
12015  CVE-2005-0809  Candidate  NotifyLink, when configured for client key retrieval, allows remote attackers to obtain AES keys via a direct request to /hwp/get.asp, then uses a weak encryption scheme (fixed byte reordering) to protect the key, which allows remote attackers to obtain the key via a brute force attack.  Assigned (20050320)  None (candidate not yet proposed)    View

Page 19636 of 20943, showing 5 records out of 104715 total, starting on record 98176, ending on 98180

Actions