CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10304  CVE-2004-1877  Candidate  The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently reveal their username and password.  Assigned (20050504)  None (candidate not yet proposed)    View
8001  CVE-2003-1177  Candidate  Buffer overflow in the base64 decoder in MERCUR Mailserver 4.2 before SP3a allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) AUTH command to the POP3 server or (2) AUTHENTICATE command to the IMAP server.  Assigned (20050504)  None (candidate not yet proposed)    View
10305  CVE-2004-1878  Candidate  LINBOX LIN:BOX allows remote attackers to bypass authentication, obtain sensitive information, or gain access via a direct request to admin/user.pl preceded by // (double leading slash).  Assigned (20050504)  None (candidate not yet proposed)    View
8002  CVE-2003-1178  Candidate  Eval injection vulnerability in comments.php in Advanced Poll 2.0.2 allows remote attackers to execute arbitrary PHP code via the (1) id, (2) template_set, or (3) action parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10306  CVE-2004-1879  Candidate  Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows allows remote attackers to inject arbitrary web script or HTML via forum messages.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 1492 of 20943, showing 5 records out of 104715 total, starting on record 7456, ending on 7460

Actions