CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11050  CVE-2004-2624  Candidate  Cross-site scripting (XSS) vulnerability in "TextSearch" in WackoWiki 3.5 allows remote attackers to inject arbitrary web script or HTML via the "phrase" parameter.  Assigned (20051204)  None (candidate not yet proposed)    View
11049  CVE-2004-2623  Candidate  Unknown vulnerability in Rippy the Aggregator before 0.10, when register_globals is enabled, has unknown attack vectors and impact, possibly related to the "user-controlled filter."  Assigned (20051204)  None (candidate not yet proposed)    View
11048  CVE-2004-2622  Candidate  AClient.exe in Altiris Deployment Solution 6.x and 5.x does not require authentication from the first Deployment Server that it connects to, which allows remote malicious servers to gain administrator access.  Assigned (20051204)  None (candidate not yet proposed)    View
11047  CVE-2004-2621  Candidate  Nortel Contivity VPN Client 2.1.7, 3.00, 3.01, 4.91, and 5.01, when opening a VPN tunnel, does not check the gateway certificate until after a dialog box has been displayed to the user, which creates a race condition that allows remote attackers to perform a man-in-the-middle (MITM) attack.  Assigned (20051204)  None (candidate not yet proposed)    View
11046  CVE-2004-2620  Candidate  The MIMEH_read_headers function in ripMIME 1.3.1.0 does not properly handle trailing " " and " " characters in headers, which leads to a buffer underflow.  Assigned (20051204)  None (candidate not yet proposed)    View

Page 18734 of 20943, showing 5 records out of 104715 total, starting on record 93666, ending on 93670

Actions