CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7958  CVE-2003-1134  Candidate  Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the ClassDepth function with a null parameter, which causes a crash instead of generating a null pointer exception.  Assigned (20050504)  None (candidate not yet proposed)    View
10262  CVE-2004-1835  Candidate  Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1) img, (2) cat, (3) sort_key, (4) order_key, (5) user, or (6) album parameters.  Assigned (20050504)  None (candidate not yet proposed)    View
7959  CVE-2003-1135  Candidate  Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send request (sendfile) with a large number of "%" (percent) characters after the Yahoo ID.  Assigned (20050504)  None (candidate not yet proposed)    View
10263  CVE-2004-1836  Candidate  SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to execute arbitrary SQL via the id parameter of the comments action.  Assigned (20050504)  None (candidate not yet proposed)    View
7960  CVE-2003-1136  Candidate  Cross-site scripting (XSS) vulnerability in Chi Kien Uong Guestbook 1.51 allows remote attackers to inject arbitrary web script or HTML via (1) HTML in a posted message or (2) Javascript in an onmouseover attribute in an e-mail address or URL.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 1475 of 20943, showing 5 records out of 104715 total, starting on record 7371, ending on 7375

Actions