CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10106  CVE-2004-1678  Candidate  Directory traversal vulnerability in pdesk.cgi in PerlDesk allows remote attackers to read portions of arbitrary files and possibly execute arbitrary Perl modules via ".." sequences terminated by a %00 (null) character in the lang parameter, which can leak portions of the requested files if a compilation error message occurs.  Assigned (20050221)  None (candidate not yet proposed)    View
10107  CVE-2004-1679  Candidate  Directory traversal vulnerability in TwinFTP 1.0.3 R2 allows remote attackers create arbitrary files via a .../ (triple dot) in the (1) CWD, (2) STOR, or (3) RETR commands.  Assigned (20050221)  None (candidate not yet proposed)    View
10108  CVE-2004-1680  Candidate  application.cgi in the Pingtel Xpressa handset running firmware 2.1.11.24 allows remote authenticated users to cause a denial of service (VxWorks OS crash) via a long HTTP GET request, possibly triggering a buffer overflow.  Assigned (20050221)  None (candidate not yet proposed)    View
10109  CVE-2004-1681  Candidate  Multiple buffer overflows in (1) phrelay-cfg, (2) phlocale, (3) pkg-installer, or (4) input-cfg in QNX Photon microGUI for QNX RTP 6.1 allow local users to gain privileges via a long -s (server) command line parameter.  Assigned (20050221)  None (candidate not yet proposed)    View
10110  CVE-2004-1682  Candidate  Format string vulnerability in QNX 6.1 FTP client allows remote authenticated users to gain group bin privileges via format string specifiers in the QUOTE command.  Assigned (20050221)  None (candidate not yet proposed)    View

Page 1218 of 20943, showing 5 records out of 104715 total, starting on record 6086, ending on 6090

Actions