CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9573 | CVE-2004-1145 | Candidate | Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows remote attackers to bypass sandbox restrictions and read or write arbitrary files. | Assigned (20041206) | None (candidate not yet proposed) | View | |
9574 | CVE-2004-1146 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in (1) main.c and (2) login.c for CVSTrac before 1.1.5 allow remote attackers to inject arbitrary HTML and web script. | Assigned (20041206) | None (candidate not yet proposed) | View | |
9575 | CVE-2004-1147 | Candidate | phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters. | Assigned (20041206) | None (candidate not yet proposed) | View | |
9576 | CVE-2004-1148 | Candidate | phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter. | Assigned (20041206) | None (candidate not yet proposed) | View | |
9577 | CVE-2004-1149 | Candidate | Computer Associates eTrust EZ Antivirus 7.0.0 to 7.0.4, including 7.0.1.4, installs its files with insecure permissions (ACLs), which allows local users to gain privileges by replacing critical programs with malicious ones, as demonstrated using VetMsg.exe. | Assigned (20041207) | None (candidate not yet proposed) | View |
Page 1005 of 20943, showing 5 records out of 104715 total, starting on record 5021, ending on 5025