CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11045  CVE-2004-2619  Candidate  ripMIME 1.3.2.3 and earlier allows remote attackers to bypass e-mail protection via a base64 MIME encoded attachment containing invalid characters that are not properly extracted.  Assigned (20051204)  None (candidate not yet proposed)    View
11044  CVE-2004-2618  Candidate  Cross-site scripting (XSS) vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the URI, directly after the initial "/" (slash).  Assigned (20051204)  None (candidate not yet proposed)    View
11043  CVE-2004-2617  Candidate  Directory traversal vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to read files outside of the web root via a .. (dot dot) directly after the initial "/" (slash) in the URI.  Assigned (20051204)  None (candidate not yet proposed)    View
11042  CVE-2004-2616  Candidate  The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to obtain sensitive information by uploading a file, which reveals the path in a success message.  Assigned (20051204)  None (candidate not yet proposed)    View
11041  CVE-2004-2615  Candidate  The documentation for CuteNews 1.3.6 and possibly other versions specifies that files under cutenews/data must be manually given world-writable permissions, which allows local users to insert false news, delete news, and possibly gain privileges or have other unknown impact.  Assigned (20051204)  None (candidate not yet proposed)    View

Page 18735 of 20943, showing 5 records out of 104715 total, starting on record 93671, ending on 93675

Actions