CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10915  CVE-2004-2489  Candidate  Format string vulnerability in IBM Informix Dynamic Server (IDS) before 9.40.xC3 allows local users to execute arbitrary code via a modified INFORMIXDIR environment variable that points to a file with format string specifiers in the filename.  Assigned (20051025)  None (candidate not yet proposed)    View
10914  CVE-2004-2488  Candidate  Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via "C:" sequences in the (1) RETR (get), (2) NLST (ls), (3) LIST (ls), (4) RNFR, or (5) RNTO FTP commands.  Assigned (20051025)  None (candidate not yet proposed)    View
10913  CVE-2004-2487  Candidate  Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via (1) "..", (2) ".." (backslash dot dot), or (3) "/../" sequences in (a) RETR (get), (b) NLST (ls), (c) LIST (ls), (d) RNFR, or (e) RNTO FTP commands.  Assigned (20051025)  None (candidate not yet proposed)    View
10912  CVE-2004-2486  Candidate  The DSS verification code in Dropbear SSH Server before 0.43 frees uninitialized variables, which might allow remote attackers to gain access.  Assigned (20051025)  None (candidate not yet proposed)    View
10911  CVE-2004-2485  Candidate  Unspecified vulnerability in PHP Live! before 2.8.2, due to a "major security problem," allows remote attackers to include arbitrary files and directories via unspecified attack vectors.  Assigned (20051025)  None (candidate not yet proposed)    View

Page 18761 of 20943, showing 5 records out of 104715 total, starting on record 93801, ending on 93805

Actions