CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10086  CVE-2004-1658  Candidate  Kerio Personal Firewall 4.0 (KPF4) allows local users with administrative privileges to bypass the Application Security feature and execute arbitrary processes by directly writing to devicephysicalmemory to restore the running kernel"s SDT ServiceTable.  Assigned (20050221)  None (candidate not yet proposed)    View
10087  CVE-2004-1659  Candidate  Cross-site scripting (XSS) vulnerability in index.php in CuteNews 1.3.6 and earlier allows remote attackers with Administrator, Editor, Journalist or Commenter privileges to inject arbitrary web script or HTML via the mod parameter.  Assigned (20050221)  None (candidate not yet proposed)    View
10088  CVE-2004-1660  Candidate  PHP remote file inclusion vulnerability in CuteNews 1.3.6 and earlier allows remote attackers to execute arbitrary PHP code via the cutepath parameter to (1) show_archives.php or (2) show_news.php.  Assigned (20050221)  None (candidate not yet proposed)    View
10089  CVE-2004-1661  Candidate  MailWorks Professional allows remote attackers to bypass authentication and gain privileges via a cookie that contains "auth=1" and "uId=1."  Assigned (20050221)  None (candidate not yet proposed)    View
10090  CVE-2004-1662  Candidate  YaBB SE 1.5.1 allows remote attackers to obtain sensitive information via a direct HTTP request to Admin.php, which reveals the full path in a PHP error message.  Assigned (20050221)  None (candidate not yet proposed)    View

Page 1214 of 20943, showing 5 records out of 104715 total, starting on record 6066, ending on 6070

Actions