CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9588 | CVE-2004-1160 | Candidate | Netscape 7.x to 7.2, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability. | Assigned (20041208) | None (candidate not yet proposed) | View | |
9589 | CVE-2004-1161 | Candidate | rssh 2.2.2 and earlier does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via (1) rdist -P, (2) rsync, or (3) scp -S. | Assigned (20041209) | None (candidate not yet proposed) | View | |
9590 | CVE-2004-1162 | Candidate | The unison command in scponly before 4.0 does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via the (1) -rshcmd or (2) -sshcmd flags. | Assigned (20041209) | None (candidate not yet proposed) | View | |
9591 | CVE-2004-1163 | Candidate | Cisco CNS Network Registrar Central Configuration Management (CCM) server 6.0 through 6.1.1.3 allows remote attackers to cause a denial of service (CPU consumption) by ending a connection after sending a certain sequence of packets. | Assigned (20041209) | None (candidate not yet proposed) | View | |
9592 | CVE-2004-1164 | Candidate | The lock manager in Cisco CNS Network Registrar 6.0 through 6.1.1.3 allows remote attackers to cause a denial of service (process crash) via a certain "unexpected packet sequence." | Assigned (20041209) | None (candidate not yet proposed) | View |
Page 1008 of 20943, showing 5 records out of 104715 total, starting on record 5036, ending on 5040