CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11769  CVE-2005-0563  Candidate  Cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) component in Exchange Server 5.5 allows remote attackers to inject arbitrary web script or HTML via an email message with an encoded javascript: URL ("jav&#X41sc
ript:") in an IMG tag.  Assigned (20050226)  None (candidate not yet proposed)    View
11770  CVE-2005-0564  Candidate  Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 through 2004, might allow remote attackers to execute arbitrary code via a .doc file with long font information.  Assigned (20050226)  None (candidate not yet proposed)    View
11751  CVE-2005-0545  Candidate  Microsoft Windows XP Pro SP2 and Windows 2000 Server SP4 running Active Directory allow local users to bypass group policies that restrict access to hidden drives by using the browse feature in Office 10 applications such as Word or Excel, or using a flash drive. NOTE: this issue has been disputed in a followup post.  Assigned (20050225)  None (candidate not yet proposed)    View
11752  CVE-2005-0546  Candidate  Multiple buffer overflows in Cyrus IMAPd before 2.2.11 may allow attackers to execute arbitrary code via (1) an off-by-one error in the imapd annotate extension, (2) an off-by-one error in "cached header handling," (3) a stack-based buffer overflow in fetchnews, or (4) a stack-based buffer overflow in imapd.  Assigned (20050225)  None (candidate not yet proposed)    View
11753  CVE-2005-0547  Candidate  Unknown vulnerability in ftpd on HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23 allows remote authenticated users to gain "unauthorized access to files."  Assigned (20050225)  None (candidate not yet proposed)    View

Page 19709 of 20943, showing 5 records out of 104715 total, starting on record 98541, ending on 98545

Actions