CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11646  CVE-2005-0440  Candidate  ELOG before 2.5.7 allows remote attackers to bypass authentication and download a configuration file that contains a sensitive write password via a modified URL.  Assigned (20050215)  None (candidate not yet proposed)    View
11647  CVE-2005-0441  Candidate  Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users to execute arbitrary code via the (1) attrib_valid function, (2) covert function, (3) declare statement, or (4) a crafted query plan, or remote authenticated users with database owner or "sa" role privileges to execute arbitrary code via (5) a crafted install java statement.  Assigned (20050215)  None (candidate not yet proposed)    View
11648  CVE-2005-0442  Candidate  Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via the language parameter.  Assigned (20050215)  None (candidate not yet proposed)    View
11649  CVE-2005-0443  Candidate  index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-site scripting (XSS) attacks via an invalid language parameter, which echoes the parameter in a PHP error message.  Assigned (20050215)  None (candidate not yet proposed)    View
11650  CVE-2005-0444  Candidate  VMware before 4.5.2.8848-r5 searches for gdk-pixbuf shared libraries using a path that includes the rrdharan world-writable temporary directory, which allows local users to execute arbitrary code.  Assigned (20050215)  None (candidate not yet proposed)    View

Page 19778 of 20943, showing 5 records out of 104715 total, starting on record 98886, ending on 98890

Actions