CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10406  CVE-2004-1980  Candidate  Directory traversal vulnerability in glossary.php in PROPS 0.6.1 allows remote attackers to view arbitrary files via a .. (dot dot) in (1) module or (2) format variables.  Assigned (20050504)  None (candidate not yet proposed)    View
10407  CVE-2004-1981  Candidate  The web interface for Crystal Reports allows remote attackers to cause a denial of service (disk exhaustion) by repeatedly requesting reports without retrieving the associated image files, which are not cleared from the image file folder.  Assigned (20050504)  None (candidate not yet proposed)    View
10408  CVE-2004-1982  Candidate  Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board"s .txt file via carriage return characters in the subject field.  Assigned (20050504)  REVIEWING(1) Christey  Christey> likely dupe with CVE-2004-2140  View
10409  CVE-2004-1983  Candidate  The arch_get_unmapped_area function in mmap.c in the PaX patches for Linux kernel 2.6, when Address Space Layout Randomization (ASLR) is enabled, allows local users to cause a denial of service (infinite loop) via unknown attack vectors.  Assigned (20050504)  None (candidate not yet proposed)    View
10410  CVE-2004-1984  Candidate  Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) phpinfo.php, (2) addpic.php, (3) config.php, (4) db_input.php, (5) displayecard.php, (6) ecard.php, (7) crop.inc.php, which reveal the full path in a PHP error message.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 1518 of 20943, showing 5 records out of 104715 total, starting on record 7586, ending on 7590

Actions