CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10975  CVE-2004-2549  Candidate  Nortel Wireless LAN (WLAN) Access Point (AP) 2220, 2221, and 2225 allow remote attackers to cause a denial of service (service crash) via a TCP request with a large string, followed by 8 newline characters, to (1) the Telnet service on TCP port 23 and (2) the HTTP service on TCP port 80, possibly due to a buffer overflow.  Assigned (20051121)  None (candidate not yet proposed)    View
10974  CVE-2004-2548  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form. NOTE: it is possible that the first attack vector is resultant from the error message issue (CVE-2004-2547).  Assigned (20051121)  None (candidate not yet proposed)    View
10973  CVE-2004-2547  Candidate  NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error message.  Assigned (20051121)  None (candidate not yet proposed)    View
10972  CVE-2004-2546  Candidate  Multiple memory leaks in Samba before 3.0.6 allow attackers to cause a denial of service (memory consumption).  Assigned (20051121)  None (candidate not yet proposed)    View
10971  CVE-2004-2545  Candidate  Secure Computing Corporation Sidewinder G2 6.1.0.01 allows remote attackers to cause a denial of service (SMTP proxy failure) via unknown attack vendors involving an "extremely busy network." NOTE: this might not be a vulnerability because the embedded monitoring sub-system automatically restarts after the failure.  Assigned (20051120)  None (candidate not yet proposed)    View

Page 18749 of 20943, showing 5 records out of 104715 total, starting on record 93741, ending on 93745

Actions