CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14765  CVE-2005-3559  Candidate  Directory traversal vulnerability in vmail.cgi in Asterisk 1.0.9 through 1.2.0-beta1 allows remote attackers to access WAV files via a .. (dot dot) in the folder parameter.  Assigned (20051116)  None (candidate not yet proposed)    View
6574  CVE-2002-2192  Candidate  Cross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1 allows remote attackers to execute arbitrary web script via (1) a Host: header when DNS wildcards are supported or (2) the query string in a "dir" request to indexed folders.  Assigned (20051116)  None (candidate not yet proposed)    View
14766  CVE-2005-3560  Candidate  Zone Labs (1) ZoneAlarm Pro 6.0, (2) ZoneAlarm Internet Security Suite 6.0, (3) ZoneAlarm Anti-Virus 6.0, (4) ZoneAlarm Anti-Spyware 6.0 through 6.1, and (5) ZoneAlarm 6.0 allow remote attackers to bypass the "Advanced Program Control and OS Firewall filters" setting via URLs in "HTML Modal Dialogs" (window.location.href) contained within JavaScript tags.  Assigned (20051116)  None (candidate not yet proposed)    View
6575  CVE-2002-2193  Candidate  Cross-site scripting (XSS) vulnerability in mojo.cgi for Mojo Mail 2.7 allows remote attackers to inject arbitrary web script via the email parameter.  Assigned (20051116)  None (candidate not yet proposed)    View
14767  CVE-2005-3561  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-2954. Reason: This candidate is a reservation duplicate of CVE-2005-2954. Notes: All CVE users should reference CVE-2005-2954 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20051116)  None (candidate not yet proposed)    View

Page 18747 of 20943, showing 5 records out of 104715 total, starting on record 93731, ending on 93735

Actions