CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8462  CVE-2004-0034  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.4.5 and earlier allow remote attackers to inject arbitrary HTML or web script via (1) the phorum_check_xss function in common.php, (2) the EditError variable in profile.php, and (3) the Error variable in login.php.  Modified (20071113)  ACCEPT(4) Armstrong, Baker, Cole, Williams | NOOP(2) Cox, Wall    View
8493  CVE-2004-0065  Candidate  Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2) placelist.php.  Modified (20071113)  ACCEPT(4) Armstrong, Baker, Cole, Williams | NOOP(2) Cox, Wall  Williams> http://sourceforge.net/project/showfiles.php?group_id=55456  View
8430  CVE-2004-0002  Candidate  The TCP MSS (maximum segment size) functionality in netinet allows remote attackers to cause a denial of service (resource exhaustion) via (1) a low MTU, which causes a large number of small packets to be produced, or (2) via a large number of packets with a small TCP payload, which cause a large number of calls to the resource-intensive sowakeup function.  Proposed (20040318)  ACCEPT(4) Armstrong, Baker, Cole, Williams | NOOP(2) Cox, Wall    View
2412  CVE-2000-0843  Candidate  Buffer overflow in pam_smb and pam_ntdom pluggable authentication modules (PAM) allow remote attackers to execute arbitrary commands via a login with a long user name.  Proposed (20001018)  ACCEPT(4) Armstrong, Baker, Collins, Magdych | MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall  Magdych> ACKNOWLEDGED-BY-VENDOR | Christey> ADDREF XF:pam-authentication-bo | Frech> XF:pam-authentication-bo(5225)  View
5044  CVE-2002-0654  Candidate  Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when a script (child process) cannot be invoked.  Modified (20071101)  ACCEPT(4) Armstrong, Baker, Cox, Foat | MODIFY(1) Frech | NOOP(1) Cole | REVIEWING(1) Wall  Frech> XF:apache-cgi-path-disclosure(9876) | XF:apache-var-path-disclosure(9875) | In description, correct product names to OS/2 and NetWare.  View

Page 1004 of 20943, showing 5 records out of 104715 total, starting on record 5016, ending on 5020

Actions