CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10486  CVE-2004-2060  Candidate  ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names.  Assigned (20050504)  None (candidate not yet proposed)    View
10231  CVE-2004-1804  Candidate  wMCam server 2.1.348 allows remote attackers to cause a denial of service (no new connections) via multiple malformed HTTP requests without the GET command.  Assigned (20050504)  None (candidate not yet proposed)    View
10487  CVE-2004-2061  Candidate  RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.  Assigned (20050504)  None (candidate not yet proposed)    View
10232  CVE-2004-1805  Candidate  Format string vulnerability in games using the Epic Games Unreal Engine 436 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in class names.  Assigned (20050504)  None (candidate not yet proposed)    View
10488  CVE-2004-2062  Candidate  SQL injection vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to execute arbitrary SQL via the (1) thread_id, (2) parent_id, or (3) mode parameters.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 1539 of 20943, showing 5 records out of 104715 total, starting on record 7691, ending on 7695

Actions