CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10945 | CVE-2004-2519 | Candidate | Gattaca Server 2003 1.1.10.0 allows remote attackers to cause a denial of service (CPU consumption) via directory specifiers in the LANGUAGE parameter to (1) index.tmpl and (2) web.tmpl, such as (a) slash "/", (b) backslash "", (c) dot ".",, (d) dot dot "..", and (e) internal slash "lang//en". | Assigned (20051025) | None (candidate not yet proposed) | View | |
10944 | CVE-2004-2518 | Candidate | Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00") to a URL or (2) an invalid LANGUAGE parameter to web.tmpl, which reveals the full installation path in an error message. | Assigned (20051025) | None (candidate not yet proposed) | View | |
10943 | CVE-2004-2517 | Candidate | myServer 0.7.1 allows remote attackers to cause a denial of service (crash) via a long HTTP POST request in a View=Logon operation to index.html. | Assigned (20051025) | None (candidate not yet proposed) | View | |
10942 | CVE-2004-2516 | Candidate | Directory traversal vulnerability in myServer 0.7 allows remote attackers to list arbitrary directories via an HTTP GET command with a large number of "./" sequences followed by "../" sequences. | Assigned (20051025) | None (candidate not yet proposed) | View | |
10941 | CVE-2004-2515 | Candidate | Format string vulnerability in VMware Workstation 4.5.2 build-8848, if running with elevated privileges, might allow local users to execute arbitrary code via format string specifiers in command line arguments. NOTE: it is not clear if there are any default or typical circumstances under which VMware would be running with privileges beyond those already available to the attackers, so this might not be a vulnerability. | Assigned (20051025) | None (candidate not yet proposed) | View |
Page 18755 of 20943, showing 5 records out of 104715 total, starting on record 93771, ending on 93775