CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11004 | CVE-2004-2578 | Candidate | phpGroupWare before 0.9.16.002 transmits the (1) header admin and (2) setup passwords in plaintext via cookies, which allows remote attackers to sniff passwords. | Assigned (20051128) | None (candidate not yet proposed) | View | |
11005 | CVE-2004-2579 | Candidate | ACLCHECK module in Novell iChain 2.3 allows attackers to bypass access control rules of an unspecified component via an unspecified attack vector involving a string that contains escape sequences represented with "overlong UTF-8 encoding." | Assigned (20051128) | None (candidate not yet proposed) | View | |
11006 | CVE-2004-2580 | Candidate | Cross-site scripting (XSS) vulnerability in Novell iChain 2.3 allows remote attackers to obtain login credentials via unspecified vectors. | Assigned (20051128) | None (candidate not yet proposed) | View | |
11007 | CVE-2004-2581 | Candidate | Novell iChain 2.3 allows attackers to cause a denial of service via a URL with a "specific string." | Assigned (20051128) | None (candidate not yet proposed) | View | |
15054 | CVE-2005-3850 | Candidate | Cross-site scripting (XSS) vulnerability in search.asp in Online Knowledge Base System (OKBSYS) Lite Edition 1.0 allows remote attackers to inject arbitrary web script or HTML via hex-encoded values in the q parameter. | Assigned (20051127) | None (candidate not yet proposed) | View |
Page 18667 of 20943, showing 5 records out of 104715 total, starting on record 93331, ending on 93335