CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11043 | CVE-2004-2617 | Candidate | Directory traversal vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to read files outside of the web root via a .. (dot dot) directly after the initial "/" (slash) in the URI. | Assigned (20051204) | None (candidate not yet proposed) | View | |
11044 | CVE-2004-2618 | Candidate | Cross-site scripting (XSS) vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the URI, directly after the initial "/" (slash). | Assigned (20051204) | None (candidate not yet proposed) | View | |
11045 | CVE-2004-2619 | Candidate | ripMIME 1.3.2.3 and earlier allows remote attackers to bypass e-mail protection via a base64 MIME encoded attachment containing invalid characters that are not properly extracted. | Assigned (20051204) | None (candidate not yet proposed) | View | |
11046 | CVE-2004-2620 | Candidate | The MIMEH_read_headers function in ripMIME 1.3.1.0 does not properly handle trailing " " and " " characters in headers, which leads to a buffer underflow. | Assigned (20051204) | None (candidate not yet proposed) | View | |
11047 | CVE-2004-2621 | Candidate | Nortel Contivity VPN Client 2.1.7, 3.00, 3.01, 4.91, and 5.01, when opening a VPN tunnel, does not check the gateway certificate until after a dialog box has been displayed to the user, which creates a race condition that allows remote attackers to perform a man-in-the-middle (MITM) attack. | Assigned (20051204) | None (candidate not yet proposed) | View |
Page 18621 of 20943, showing 5 records out of 104715 total, starting on record 93101, ending on 93105