CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10910 | CVE-2004-2484 | Candidate | Cross-site scripting (XSS) vulnerability in PHP Gift Registry 1.3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter to (1) event.php or (2) index.php. | Assigned (20051025) | None (candidate not yet proposed) | View | |
10909 | CVE-2004-2483 | Candidate | Kerio WinRoute Firewall before 6.0.9 uses information from PTR queries in response to A queries, which allows remote attackers to poison the DNS cache or cause a denial of service (connection loss). | Assigned (20050821) | None (candidate not yet proposed) | View | |
10908 | CVE-2004-2482 | Candidate | Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to automatically download the URI in the data property of the OBJECT tag and might allow remote attackers to execute arbitrary code. | Assigned (20050821) | None (candidate not yet proposed) | View | |
10907 | CVE-2004-2481 | Candidate | MyProxy 6.58 allows remote authenticated users in the Users Tab to connect to arbitrary hosts from the MyProxy server, possibly bypassing access restrictions, by connecting to the proxy and issuing a CONNECT command. | Assigned (20050821) | None (candidate not yet proposed) | View | |
10906 | CVE-2004-2480 | Candidate | Squid Web Proxy Cache 2.3.STABLE5 allows remote attackers to bypass security controls and access arbitrary websites via "@@" sequences in a URL within Internet Explorer. | Assigned (20050821) | None (candidate not yet proposed) | View |
Page 18762 of 20943, showing 5 records out of 104715 total, starting on record 93806, ending on 93810