CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2308  CVE-2000-0732  Entry  Worm HTTP server allows remote attackers to cause a denial of service via a long URL.        View
39446  CVE-2009-2011  Candidate  Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a plug-in for Firefox, does not restrict access to the shell.execute JavaScript API method, which allows remote attackers to execute arbitrary commands via a .dxstudio file that invokes this method.  Assigned (20090608)  None (candidate not yet proposed)    View
15470  CVE-2005-4266  Candidate  WorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated with a username, which allows remote attackers to perform actions as other users by guessing or sniffing the random value.  Assigned (20051215)  None (candidate not yet proposed)    View
15413  CVE-2005-4209  Candidate  WorldClient webmail in Alt-N MDaemon 8.1.3 allows remote attackers to prevent arbitrary users from accessing their inboxes via script tags in the Subject header of an e-mail message, which prevents the user from being able to access the Inbox folder, possibly due to a cross-site scripting (XSS) vulnerability.  Assigned (20051213)  None (candidate not yet proposed)    View
2292  CVE-2000-0716  Entry  WorldClient email client in MDaemon 2.8 includes the session ID in the referer field of an HTTP request when the user clicks on a URL, which allows the visited web site to hijack the session ID and read the user"s email.        View

Page 140 of 20943, showing 5 records out of 104715 total, starting on record 696, ending on 700

Actions