CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10910  CVE-2004-2484  Candidate  Cross-site scripting (XSS) vulnerability in PHP Gift Registry 1.3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter to (1) event.php or (2) index.php.  Assigned (20051025)  None (candidate not yet proposed)    View
10909  CVE-2004-2483  Candidate  Kerio WinRoute Firewall before 6.0.9 uses information from PTR queries in response to A queries, which allows remote attackers to poison the DNS cache or cause a denial of service (connection loss).  Assigned (20050821)  None (candidate not yet proposed)    View
10908  CVE-2004-2482  Candidate  Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to automatically download the URI in the data property of the OBJECT tag and might allow remote attackers to execute arbitrary code.  Assigned (20050821)  None (candidate not yet proposed)    View
10907  CVE-2004-2481  Candidate  MyProxy 6.58 allows remote authenticated users in the Users Tab to connect to arbitrary hosts from the MyProxy server, possibly bypassing access restrictions, by connecting to the proxy and issuing a CONNECT command.  Assigned (20050821)  None (candidate not yet proposed)    View
10906  CVE-2004-2480  Candidate  Squid Web Proxy Cache 2.3.STABLE5 allows remote attackers to bypass security controls and access arbitrary websites via "@@" sequences in a URL within Internet Explorer.  Assigned (20050821)  None (candidate not yet proposed)    View

Page 18762 of 20943, showing 5 records out of 104715 total, starting on record 93806, ending on 93810

Actions