CVE List

Id CVE No. Status Description Phase Votes Comments Actions
42195  CVE-2009-4760  Candidate  Winn ASP Guestbook 1.01 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/guestbook.mdb.  Assigned (20100329)  None (candidate not yet proposed)    View
4059  CVE-2001-1255  Candidate  WinMySQLadmin 1.1 stores the MySQL password in plain text in the my.ini file, which allows local users to obtain unathorized access the MySQL database.  Proposed (20020502)  ACCEPT(2) Frech, Green | NOOP(5) Christey, Cole, Cox, Foat, Wall  Christey> fix typos: "unathorized"; "[TO] the database"  View
24849  CVE-2007-1492  Candidate  winmm.dll in Microsoft Windows XP allows user-assisted remote attackers to cause a denial of service (infinite loop) via a large cch argument value to the mmioRead function, as demonstrated by a crafted WAV file.  Assigned (20070316)  None (candidate not yet proposed)    View
21266  CVE-2006-5162  Candidate  wininet.dll in Microsoft Internet Explorer 6.0 SP2 and earlier allows remote attackers to cause a denial of service (unhandled exception and crash) via a long Content-Type header, which triggers a stack overflow.  Assigned (20061003)  None (candidate not yet proposed)    View
28321  CVE-2007-4964  Candidate  WinImage 8.10 and earlier allows remote attackers to cause a denial of service (infinite loop) via an invalid BPB_BytsPerSec field in the header of a .IMG file.  Assigned (20070918)  None (candidate not yet proposed)    View

Page 167 of 20943, showing 5 records out of 104715 total, starting on record 831, ending on 835

Actions