CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4217  CVE-2001-1414  Candidate  The Basic Security Module (BSM) for Solaris 2.5.1, 2.6, 7, and 8 does not log anonymous FTP access, which allows remote attackers to hide their activities, possibly when certain BSM audit files are not present under the FTP root.  Assigned (20050208)  None (candidate not yet proposed)    View
11447  CVE-2005-0241  Candidate  The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size.  Assigned (20050208)  None (candidate not yet proposed)    View
11448  CVE-2005-0242  Candidate  The Audio Setup Wizard (asw.dll) in Yahoo! Messenger 6.0.0.1750, and possibly other versions, allows attackers to arbitrary code by placing a malicious ping.exe program into the Messenger program directory, which is installed with weak default permissions.  Assigned (20050208)  None (candidate not yet proposed)    View
11449  CVE-2005-0243  Candidate  Yahoo! Messenger 6.0.0.1750, and possibly other versions before 6.0.0.1921, does not properly display long filenames in file dialog boxes, which could allow remote attackers to trick users into downloading and executing programs via file names containing a large number of spaces and multiple file extensions.  Assigned (20050208)  None (candidate not yet proposed)    View
11450  CVE-2005-0244  Candidate  PostgreSQL 8.0.0 and earlier allows local users to bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command.  Assigned (20050208)  None (candidate not yet proposed)    View

Page 19834 of 20943, showing 5 records out of 104715 total, starting on record 99166, ending on 99170

Actions