CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11120 | CVE-2004-2694 | Candidate | Microsoft Outlook Express 6.0 allows remote attackers to bypass intended access restrictions, load content from arbitrary sources into the Outlook context, and facilitate phishing attacks via a "BASE HREF" with the target set to "_top". | Assigned (20071006) | None (candidate not yet proposed) | View | |
11119 | CVE-2004-2693 | Candidate | HP-UX B.11.00 and B.11.11 with B6848AB GTK+ Support Libraries installed uses insecure directory permissions, which allows local users to gain privileges via files in /opt/gnome/src/GLib/. | Assigned (20071006) | None (candidate not yet proposed) | View | |
11118 | CVE-2004-2692 | Candidate | The exec_dir PHP patch (php-exec-dir) 4.3.2 through 4.3.7 with safe mode disabled allows remote attackers to bypass restrictions and execute arbitrary commands via a backtick operator, which is not handled using the php_escape_shell_cmd function. | Assigned (20071006) | None (candidate not yet proposed) | View | |
11117 | CVE-2004-2691 | Candidate | Unspecified vulnerability in 3Com SuperStack 3 4400 switches with firmware version before 3.31 allows remote attackers to cause a denial of service (device reset) via a crafted request to the web management interface. NOTE: the provenance of this information is unknown; details are obtained from third party reports. | Assigned (20071006) | None (candidate not yet proposed) | View | |
11116 | CVE-2004-2690 | Candidate | Unrestricted file upload vulnerability in the Administration Panel for NewsPHP allows remote authenticated administrators to upload and execute arbitrary code instead of video files. | Assigned (20071006) | None (candidate not yet proposed) | View |
Page 18720 of 20943, showing 5 records out of 104715 total, starting on record 93596, ending on 93600