CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11000  CVE-2004-2574  Candidate  Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to inject arbitrary web script or HTML via the date parameter in a calendar.uicalendar.planner menuaction.  Assigned (20051128)  None (candidate not yet proposed)    View
10999  CVE-2004-2573  Candidate  PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to execute arbitrary PHP code via an external URL in the appdir parameter.  Assigned (20051128)  None (candidate not yet proposed)    View
10998  CVE-2004-2572  Candidate  AMAX Magic Winmail Server 3.6 allows remote attackers to obtain sensitive information by entering (1) invalid characters such as "()" or (2) a large number of characters in the Lookup field on the netaddressbook.php web form, which reveals the path in an ldaplib.php error message when the ldap_search function fails, due to improper processing of the $keyword variable.  Assigned (20051122)  None (candidate not yet proposed)    View
10997  CVE-2004-2571  Candidate  Multiple buffer overflows in EnderUNIX isoqlog 2.1.1 allow remote attackers to execute arbitrary code via the (1) parseQmailFromBytesLine, (2) parseQmailToRemoteLine, (3) parseQmailToLocalLine, (4) parseSendmailFromBytesLine, (5) parseSendmailToLine, (6) parseEximFromBytesLine, and (7) parseEximToLine functions in Parser.c; allow local users to execute arbitrary code via the (8) lowercase and (9) check_syslog_date functions in Parser.c, and (10) unspecified functions in Dir.c; and allow unspecified attackers to execute arbitrary code via the (11) loadconfig and (12) removespaces functions in loadconfig.c, the (13) loadLang function in LangCfg.c, and (14) unspecified functions in Html.c.  Assigned (20051122)  None (candidate not yet proposed)    View
10996  CVE-2004-2570  Candidate  Opera before 7.54 allows remote attackers to modify properties and methods of the location object and execute Javascript to read arbitrary files from the client"s local filesystem or display a false URL to the user.  Assigned (20051122)  None (candidate not yet proposed)    View

Page 18744 of 20943, showing 5 records out of 104715 total, starting on record 93716, ending on 93720

Actions