CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8519  CVE-2004-0091  Candidate  ** DISPUTED ** NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. NOTE: the vendor has disputed this issue, saying "There is no hidden field called "reg_site", nor any $reg_site variable anywhere in the vBulletin 2 or vBulletin 3 source code or templates, nor has it ever existed. We can only assume that this vulnerability was found in a site running code modified from that supplied by Jelsoft."  Modified (20051208)  NOOP(4) Armstrong, Cole, Cox, Wall | REVIEWING(1) Green    View
8724  CVE-2004-0296  Candidate  TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a TsFtpSrv.exe to exit with an exception by opening and immediately closing a connection.  Modified (20050707)  NOOP(4) Armstrong, Cole, Cox, Wall | REVIEWING(1) Christey  Christey> The description is incomplete. Wonder what it was about the | original researcher that was important enough to note? | Christey> What was I saying in the desc about the original researcher???  View
5929  CVE-2002-1545  Candidate  CooolSoft Personal FTP Server 2.24 allows remote attackers to obtain the absolute pathname of the FTP root via a PWD command, which includes the full path in the response.  Proposed (20030317)  NOOP(4) Armstrong, Cole, Cox, Wall | REVIEWING(1) Christey  Christey> This seems like a rediscovery of CVE-2001-0934.  View
8683  CVE-2004-0255  Candidate  Xlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long directory consisting of . (dot) and / (slash) characters, which causes the server to crash when the administrator views the log file, possibly triggering a buffer overflow.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall | REVIEWING(1) Christey  Christey> MISC:http://www.xlightftpd.com/forum/viewtopic.php?t=40 | In the above URL, the vendor says that only one of 3 bugs | reported in February 2004 were an "actual server bug," and the other 2 | "traced back into windows" dll and they won"t happen if windows | service pack is installed. | | The "actual server bug" is CVE-2004-0287. The demonstration | for *this* issue shows that the application breaks in comctl32.dll. | So, this candidate may be erroneous, and an interesting side effect of | another bug that"s not related to xlight at all. | | Thus, this candidate may need to be REJECTED.  View
8706  CVE-2004-0278  Candidate  Ratbag game engine, as used in products such as Dirt Track Racing, Leadfoot, and World of Outlaws Spring Cars, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet that specifies the length of data to read and then sends a second TCP packet that contains less data than specified, which causes Ratbag to repeatedly check the socket for more data.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View

Page 13 of 20943, showing 5 records out of 104715 total, starting on record 61, ending on 65

<<first 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 last>>

Actions