NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
69008  CVE-2005-3346  Buffer overflow in the environment variable substitution code in main.c in OSH 1.7-14 allows local users to inject arbitrary environment variables, such as LD_PRELOAD, via pathname arguments of the form "$VAR/EVAR=arg", which cause the EVAR portion to be appended to a buffer returned by a getenv function call.    7.2  High  2017-07-18  2017-07-10  View
69009  CVE-2005-3347  Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egrouwpware before 1.0.0.009, allow remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) sensor_program parameter or the (2) _SERVER[HTTP_ACCEPT_LANGUAGE] parameter, which overwrites an internal variable, a variant of CVE-2003-0536. NOTE: due to a typo in an advisory, an issue in osh was inadvertently linked to this identifier; the proper identifier for the osh issue is CVE-2005-3346.    6.8  Medium  2017-07-18  2017-07-10  View
69010  CVE-2005-3348  HTTP response splitting vulnerability in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egroupware before 1.0.0.009, allows remote attackers to spoof web content and poison web caches via CRLF sequences in the charset parameter.    4.3  Medium  2017-07-18  2017-07-10  View
69011  CVE-2005-3349  GNU Gnump3d before 2.9.8 allows local users to modify or delete arbitrary files via a symlink attack on the index.lok temporary file.    1.9  Low  2017-01-03  2011-10-18  View
69012  CVE-2005-3350  libungif library before 4.1.0 allows attackers to corrupt memory and possibly execute arbitrary code via a crafted GIF file that leads to an out-of-bounds write.    7.5  High  2017-01-03  2011-03-07  View

Page 2826 of 17672, showing 5 records out of 88360 total, starting on record 14126, ending on 14130

Actions