CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11115 | CVE-2004-2689 | Candidate | NewsPHP allows remote attackers to gain unauthorized administrative access by setting a cookie to the "autorized=admin; root=admin" value. | Assigned (20071006) | None (candidate not yet proposed) | View | |
11114 | CVE-2004-2688 | Candidate | Cross-site scripting (XSS) vulnerability in index.php in NewsPHP allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter. NOTE: this issue might overlap vector 3 in CVE-2006-3358. | Assigned (20071006) | None (candidate not yet proposed) | View | |
11113 | CVE-2004-2687 | Candidate | distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization checks. | Assigned (20070923) | None (candidate not yet proposed) | View | |
11112 | CVE-2004-2686 | Candidate | Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load arbitrary kernel modules via crafted (1) mount or (2) sysfs system calls. NOTE: this might be the same issue as CVE-2004-1767, but there are insufficient details to be sure. | Assigned (20070923) | None (candidate not yet proposed) | View | |
11111 | CVE-2004-2685 | Candidate | Buffer overflow in YoungZSoft CCProxy 6.2 and earlier allows remote attackers to execute arbitrary code via a long address in a ping (p) command to the Telnet proxy service, a different vector than CVE-2004-2416. | Assigned (20070906) | None (candidate not yet proposed) | View |
Page 18721 of 20943, showing 5 records out of 104715 total, starting on record 93601, ending on 93605