CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10143  CVE-2004-1715  Candidate  Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 allows remote attackers or local users to read arbitrary files via "..\", "..", and similar dot dot sequences in the URL.  Assigned (20050226)  None (candidate not yet proposed)    View
10144  CVE-2004-1716  Candidate  Cross-site scripting (XSS) vulnerability in PForum before 1.26 allows remote attackers to inject arbitrary web script or HTML via the (1) IRC Server or (2) AIM ID fields in the user profile.  Assigned (20050226)  None (candidate not yet proposed)    View
10145  CVE-2004-1717  Candidate  Multiple buffer overflows in the psscan function in ps.c for gv (ghostview) allow remote attackers to execute arbitrary code via a Postscript file with a long (1) BoundingBox, (2) comment, (3) Orientation, (4) PageOrder, or (5) Pages value.  Assigned (20050226)  None (candidate not yet proposed)    View
10146  CVE-2004-1718  Candidate  The ZwOpenSection function in Integrity Protection Driver (IPD) 1.4 and earlier allows local users to cause a denial of service (crash) via an invalid pointer in the "oa" argument.  Assigned (20050226)  None (candidate not yet proposed)    View
10147  CVE-2004-1719  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) category, (2) cserver, (3) ext, (4) global, (5) showgroups, (6) or showlite parameters to address.html, or the (7) spage or (8) autoresponder parameters to settings.html, the (9) folder parameter to readmail.html, or the (10) attachmentpage_text_error parameter to attachment.html, (11) folder, (12) ct, or (13) cv parameters to calendar.html, (14) an <img> tag, or (15) the subject of an e-mail message.  Assigned (20050226)  None (candidate not yet proposed)    View

Page 1238 of 20943, showing 5 records out of 104715 total, starting on record 6186, ending on 6190

Actions