CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9633 | CVE-2004-1205 | Candidate | codebrowserpntm.php in PnTresMailer 6.03 allows remote attackers to gain sensitive information via an invalid filetohighlight parameter, which reveals the full path in an error message. | Assigned (20041214) | None (candidate not yet proposed) | View | |
9634 | CVE-2004-1206 | Candidate | Directory traversal vulnerability in codebrowserpntm.php in pnTresMailer 6.0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the filetodownload parameter. | Assigned (20041214) | None (candidate not yet proposed) | View | |
9635 | CVE-2004-1207 | Candidate | The Serious engine, as used in (1) Alpha Black Zero Intrepid Protocol 1.04 and earlier, (2) Nitro family, and (3) Serious Sam Second Encounter 1.07 allows remote attackers to cause a denial of service (server crash) via a large number of UDP join requests that exceeds the maximum player limit, as originally reported for Alpha Black Zero. | Assigned (20041214) | None (candidate not yet proposed) | View | |
9636 | CVE-2004-1208 | Candidate | Buffer overflow in Orbz 2.10 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long password field in a join request. | Assigned (20041214) | None (candidate not yet proposed) | View | |
9637 | CVE-2004-1209 | Candidate | Verisign Payflow Link, when running with empty Accepted URL fields, does not properly verify the data in the hidden AMOUNT field, which allows remote attackers to modify the price of the items that they purchase. | Assigned (20041214) | None (candidate not yet proposed) | View |
Page 1017 of 20943, showing 5 records out of 104715 total, starting on record 5081, ending on 5085