CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7998  CVE-2003-1174  Candidate  Buffer overflow in NullSoft Shoutcast Server 1.9.2 allows local users to cause a denial of service via (1) icy-name followed by a long server name or (2) icy-url followed by a long URL.  Assigned (20050504)  None (candidate not yet proposed)    View
10302  CVE-2004-1875  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to testfile.html, (2) file parameter to erredit.html, (3) dns parameter to dnslook.html, (4) account parameter to ignorelist.html, (5) account parameter to showlog.html, (6) db parameter to repairdb.html, (7) login parameter to doaddftp.html (8) account parameter to editmsg.htm, or (9) ip parameter to del.html. NOTE: the dnslook.html vector was later reported to exist in cPanel 10.  Assigned (20050504)  None (candidate not yet proposed)    View
7999  CVE-2003-1175  Candidate  Cross-site scripting (XSS) vulnerability in index.php in Sympoll 1.5 allows remote attackers to inject arbitrary web script or HTML via the vo parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10303  CVE-2004-1876  Candidate  The "%f" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) before 0.70 allows local users to execute arbitrary commands via shell metacharacters in a file name.  Assigned (20050504)  None (candidate not yet proposed)    View
8000  CVE-2003-1176  Candidate  post_message_form.asp in Web Wiz Forums 6.34 through 7.5, when quote mode is used, allows remote attackers to read or write to private forums by modifying the FID (forum ID) parameter.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 1491 of 20943, showing 5 records out of 104715 total, starting on record 7451, ending on 7455

Actions