CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10905 | CVE-2004-2479 | Candidate | Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages. | Assigned (20050821) | None (candidate not yet proposed) | View | |
10904 | CVE-2004-2478 | Candidate | Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | Assigned (20050821) | None (candidate not yet proposed) | View | |
10903 | CVE-2004-2477 | Candidate | DiamondCS Process Guard Free 2.000 allows local users to disable the process guard protection system by overwriting the current Service Descriptor Table (SDT) in devicephysicalmemory with the original SDT found in ntoskrnl.exe. | Assigned (20050821) | None (candidate not yet proposed) | View | |
10902 | CVE-2004-2476 | Candidate | Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop and crash) via an IFRAME with "?" as the file source. | Assigned (20050820) | None (candidate not yet proposed) | View | |
10901 | CVE-2004-2475 | Candidate | Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the About section. NOTE: some followup posts suggest that the demonstration code"s use of the res:// protocol does not cross privilege boundaries, since it is not allowed in the Internet Zone. Thus this might not be a vulnerability. | Assigned (20050820) | None (candidate not yet proposed) | View |
Page 18763 of 20943, showing 5 records out of 104715 total, starting on record 93811, ending on 93815