CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11043  CVE-2004-2617  Candidate  Directory traversal vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to read files outside of the web root via a .. (dot dot) directly after the initial "/" (slash) in the URI.  Assigned (20051204)  None (candidate not yet proposed)    View
11044  CVE-2004-2618  Candidate  Cross-site scripting (XSS) vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the URI, directly after the initial "/" (slash).  Assigned (20051204)  None (candidate not yet proposed)    View
11045  CVE-2004-2619  Candidate  ripMIME 1.3.2.3 and earlier allows remote attackers to bypass e-mail protection via a base64 MIME encoded attachment containing invalid characters that are not properly extracted.  Assigned (20051204)  None (candidate not yet proposed)    View
11046  CVE-2004-2620  Candidate  The MIMEH_read_headers function in ripMIME 1.3.1.0 does not properly handle trailing " " and " " characters in headers, which leads to a buffer underflow.  Assigned (20051204)  None (candidate not yet proposed)    View
11047  CVE-2004-2621  Candidate  Nortel Contivity VPN Client 2.1.7, 3.00, 3.01, 4.91, and 5.01, when opening a VPN tunnel, does not check the gateway certificate until after a dialog box has been displayed to the user, which creates a race condition that allows remote attackers to perform a man-in-the-middle (MITM) attack.  Assigned (20051204)  None (candidate not yet proposed)    View

Page 18621 of 20943, showing 5 records out of 104715 total, starting on record 93101, ending on 93105

Actions