CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12960  CVE-2005-1754  Candidate  ** DISPUTED ** JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary files via a full pathname in the argument to the Download parameter. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products."  Assigned (20050526)  None (candidate not yet proposed)    View
12961  CVE-2005-1755  Candidate  PHP remote file inclusion vulnerability in poll_vote.php in PHP Poll Creator 1.01 allows remote attackers to execute arbitrary PHP code via the relativer_pfad parameter.  Assigned (20050526)  None (candidate not yet proposed)    View
10520  CVE-2004-2094  Candidate  Cross-site scripting (XSS) vulnerability in WebcamXP 1.06.945 allows remote attackers to inject arbitrary HTML or web script as other users via a URL that contains the script.  Assigned (20050527)  None (candidate not yet proposed)    View
10521  CVE-2004-2095  Candidate  Honeyd before 0.8 replies to TCP packets with the SYN and RST flags set, which allows remote attackers to identify IP addresses that are being simulated by Honeyd.  Assigned (20050527)  None (candidate not yet proposed)    View
10522  CVE-2004-2096  Candidate  Cross-site scripting (XSS) vulnerability in Mephistoles httpd 0.6.0 final allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the URL.  Assigned (20050527)  None (candidate not yet proposed)    View

Page 1611 of 20943, showing 5 records out of 104715 total, starting on record 8051, ending on 8055

Actions