CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11945  CVE-2005-0739  Candidate  The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the dissect_pdus and pduval_to_str functions.  Assigned (20050313)  None (candidate not yet proposed)    View
11946  CVE-2005-0740  Candidate  The TCP stack (tcp_input.c) in OpenBSD 3.5 and 3.6 allows remote attackers to cause a denial of service (system panic) via crafted values in the TCP timestamp option, which causes invalid arguments to be used when calculating the retransmit timeout.  Assigned (20050313)  None (candidate not yet proposed)    View
11947  CVE-2005-0741  Candidate  Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a usersrecentposts action.  Assigned (20050313)  None (candidate not yet proposed)    View
11948  CVE-2005-0742  Candidate  Cross-site scripting (XSS) vulnerability in Sun Java System Application Server 7 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.  Assigned (20050313)  None (candidate not yet proposed)    View
11949  CVE-2005-0743  Candidate  The custom avatar uploading feature (uploader.php) for XOOPS 2.0.9.2 and earlier allows remote attackers to upload arbitrary PHP scripts, whose file extensions are not filtered.  Assigned (20050313)  None (candidate not yet proposed)    View

Page 19647 of 20943, showing 5 records out of 104715 total, starting on record 98231, ending on 98235

Actions