CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10373  CVE-2004-1947  Candidate  The AVXSCANONLINE.AvxScanOnlineCtrl.1 ActiveX control in BitDefender Scan Online allows remote attackers to (1) obtain sensitive information such as system drives and contents or (2) use the RequestFile method to download and execute arbitrary code via an object codebase that uses bitdefender.cab.  Assigned (20050504)  None (candidate not yet proposed)    View
10374  CVE-2004-1948  Candidate  NcFTP client 3.1.6 and 3.1.7, when the username and password are included in an FTP URL that is provided on the command line, allows local users to obtain sensitive information via "ps aux," which displays the URL in the process list.  Assigned (20050504)  None (candidate not yet proposed)    View
10375  CVE-2004-1949  Candidate  SQL injection vulnerability in PostNuke 7.2.6 and earlier allows remote attackers to execute arbitrary SQL via (1) the sif parameter to index.php in the Comments module or (2) timezoneoffset parameter to changeinfo.php in the Your_Account module.  Assigned (20050504)  None (candidate not yet proposed)    View
10376  CVE-2004-1950  Candidate  phpBB 2.0.8a and earlier trusts the IP address that is in the X-Forwarded-For in the HTTP header, which allows remote attackers to spoof IP addresses.  Assigned (20050504)  None (candidate not yet proposed)    View
10377  CVE-2004-1951  Candidate  xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) audio.sun_audio_device or (2) dxr3.devicename options in an MRL link.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 1511 of 20943, showing 5 records out of 104715 total, starting on record 7551, ending on 7555

Actions