CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6399 | CVE-2002-2017 | Candidate | sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, which is then executed by sastcpd. | Assigned (20050714) | None (candidate not yet proposed) | View | |
13482 | CVE-2005-2276 | Candidate | Cross-site scripting (XSS) vulnerability in Novell Groupwise WebAccess 6.5 before July 11, 2005 allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an encoded javascript URI (e.g. "jAvascript" in an IMG tag. | Assigned (20050715) | None (candidate not yet proposed) | View | |
13483 | CVE-2005-2277 | Candidate | Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename argument of a PUT command. | Assigned (20050715) | None (candidate not yet proposed) | View | |
10639 | CVE-2004-2213 | Candidate | Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to obtain the source code for scripts via a (1) trailing dot (".") or (2) trailing space in an HTTP request. | Assigned (20050717) | None (candidate not yet proposed) | View | |
10640 | CVE-2004-2214 | Candidate | Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions via a URI with mixed case characters. | Assigned (20050717) | None (candidate not yet proposed) | View |
Page 1845 of 20943, showing 5 records out of 104715 total, starting on record 9221, ending on 9225