CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6399  CVE-2002-2017  Candidate  sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, which is then executed by sastcpd.  Assigned (20050714)  None (candidate not yet proposed)    View
13482  CVE-2005-2276  Candidate  Cross-site scripting (XSS) vulnerability in Novell Groupwise WebAccess 6.5 before July 11, 2005 allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an encoded javascript URI (e.g. "j&#X41vascript" in an IMG tag.  Assigned (20050715)  None (candidate not yet proposed)    View
13483  CVE-2005-2277  Candidate  Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename argument of a PUT command.  Assigned (20050715)  None (candidate not yet proposed)    View
10639  CVE-2004-2213  Candidate  Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to obtain the source code for scripts via a (1) trailing dot (".") or (2) trailing space in an HTTP request.  Assigned (20050717)  None (candidate not yet proposed)    View
10640  CVE-2004-2214  Candidate  Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions via a URI with mixed case characters.  Assigned (20050717)  None (candidate not yet proposed)    View

Page 1845 of 20943, showing 5 records out of 104715 total, starting on record 9221, ending on 9225

Actions