CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10373 | CVE-2004-1947 | Candidate | The AVXSCANONLINE.AvxScanOnlineCtrl.1 ActiveX control in BitDefender Scan Online allows remote attackers to (1) obtain sensitive information such as system drives and contents or (2) use the RequestFile method to download and execute arbitrary code via an object codebase that uses bitdefender.cab. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10374 | CVE-2004-1948 | Candidate | NcFTP client 3.1.6 and 3.1.7, when the username and password are included in an FTP URL that is provided on the command line, allows local users to obtain sensitive information via "ps aux," which displays the URL in the process list. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10375 | CVE-2004-1949 | Candidate | SQL injection vulnerability in PostNuke 7.2.6 and earlier allows remote attackers to execute arbitrary SQL via (1) the sif parameter to index.php in the Comments module or (2) timezoneoffset parameter to changeinfo.php in the Your_Account module. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10376 | CVE-2004-1950 | Candidate | phpBB 2.0.8a and earlier trusts the IP address that is in the X-Forwarded-For in the HTTP header, which allows remote attackers to spoof IP addresses. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10377 | CVE-2004-1951 | Candidate | xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) audio.sun_audio_device or (2) dxr3.devicename options in an MRL link. | Assigned (20050504) | None (candidate not yet proposed) | View |
Page 1511 of 20943, showing 5 records out of 104715 total, starting on record 7551, ending on 7555