CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11115  CVE-2004-2689  Candidate  NewsPHP allows remote attackers to gain unauthorized administrative access by setting a cookie to the "autorized=admin; root=admin" value.  Assigned (20071006)  None (candidate not yet proposed)    View
11114  CVE-2004-2688  Candidate  Cross-site scripting (XSS) vulnerability in index.php in NewsPHP allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter. NOTE: this issue might overlap vector 3 in CVE-2006-3358.  Assigned (20071006)  None (candidate not yet proposed)    View
11113  CVE-2004-2687  Candidate  distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization checks.  Assigned (20070923)  None (candidate not yet proposed)    View
11112  CVE-2004-2686  Candidate  Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load arbitrary kernel modules via crafted (1) mount or (2) sysfs system calls. NOTE: this might be the same issue as CVE-2004-1767, but there are insufficient details to be sure.  Assigned (20070923)  None (candidate not yet proposed)    View
11111  CVE-2004-2685  Candidate  Buffer overflow in YoungZSoft CCProxy 6.2 and earlier allows remote attackers to execute arbitrary code via a long address in a ping (p) command to the Telnet proxy service, a different vector than CVE-2004-2416.  Assigned (20070906)  None (candidate not yet proposed)    View

Page 18721 of 20943, showing 5 records out of 104715 total, starting on record 93601, ending on 93605

Actions