CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10038  CVE-2004-1610  Candidate  SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.AttachmentPath or (2) vMME.LibraryPath variables.  Assigned (20050220)  None (candidate not yet proposed)    View
10039  CVE-2004-1611  Candidate  SalesLogix 6.1 does not verify if a user is authenticated before performing sensitive operations, which could allow remote attackers to (1) execute arbitrary SLX commands on the server or spoof the server via a man-in-the-middle (MITM) attack, or (2) obtain the database password via a GetConnection request to TCP port 1707.  Assigned (20050220)  None (candidate not yet proposed)    View
10040  CVE-2004-1612  Candidate  Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a ProcessQueueFile request.  Assigned (20050220)  None (candidate not yet proposed)    View
10041  CVE-2004-1613  Candidate  Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a (1) TEXTAREA, (2) INPUT, (3) FRAMESET or (4) IMG tag followed by a null character and some trailing characters, as demonstrated by mangleme.  Assigned (20050220)  None (candidate not yet proposed)    View
10042  CVE-2004-1614  Candidate  Mozilla allows remote attackers to cause a denial of service (application crash from invalid memory access) via an "unusual combination of visual elements," including several large MARQUEE tags with large height parameters, as demonstrated by mangleme.  Assigned (20050220)  None (candidate not yet proposed)    View

Page 1202 of 20943, showing 5 records out of 104715 total, starting on record 6006, ending on 6010

Actions