CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9573  CVE-2004-1145  Candidate  Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows remote attackers to bypass sandbox restrictions and read or write arbitrary files.  Assigned (20041206)  None (candidate not yet proposed)    View
9574  CVE-2004-1146  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in (1) main.c and (2) login.c for CVSTrac before 1.1.5 allow remote attackers to inject arbitrary HTML and web script.  Assigned (20041206)  None (candidate not yet proposed)    View
9575  CVE-2004-1147  Candidate  phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters.  Assigned (20041206)  None (candidate not yet proposed)    View
9576  CVE-2004-1148  Candidate  phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter.  Assigned (20041206)  None (candidate not yet proposed)    View
9577  CVE-2004-1149  Candidate  Computer Associates eTrust EZ Antivirus 7.0.0 to 7.0.4, including 7.0.1.4, installs its files with insecure permissions (ACLs), which allows local users to gain privileges by replacing critical programs with malicious ones, as demonstrated using VetMsg.exe.  Assigned (20041207)  None (candidate not yet proposed)    View

Page 1005 of 20943, showing 5 records out of 104715 total, starting on record 5021, ending on 5025

Actions