CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9588  CVE-2004-1160  Candidate  Netscape 7.x to 7.2, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.  Assigned (20041208)  None (candidate not yet proposed)    View
9589  CVE-2004-1161  Candidate  rssh 2.2.2 and earlier does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via (1) rdist -P, (2) rsync, or (3) scp -S.  Assigned (20041209)  None (candidate not yet proposed)    View
9590  CVE-2004-1162  Candidate  The unison command in scponly before 4.0 does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via the (1) -rshcmd or (2) -sshcmd flags.  Assigned (20041209)  None (candidate not yet proposed)    View
9591  CVE-2004-1163  Candidate  Cisco CNS Network Registrar Central Configuration Management (CCM) server 6.0 through 6.1.1.3 allows remote attackers to cause a denial of service (CPU consumption) by ending a connection after sending a certain sequence of packets.  Assigned (20041209)  None (candidate not yet proposed)    View
9592  CVE-2004-1164  Candidate  The lock manager in Cisco CNS Network Registrar 6.0 through 6.1.1.3 allows remote attackers to cause a denial of service (process crash) via a certain "unexpected packet sequence."  Assigned (20041209)  None (candidate not yet proposed)    View

Page 1008 of 20943, showing 5 records out of 104715 total, starting on record 5036, ending on 5040

Actions