CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10905  CVE-2004-2479  Candidate  Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages.  Assigned (20050821)  None (candidate not yet proposed)    View
10904  CVE-2004-2478  Candidate  Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.  Assigned (20050821)  None (candidate not yet proposed)    View
10903  CVE-2004-2477  Candidate  DiamondCS Process Guard Free 2.000 allows local users to disable the process guard protection system by overwriting the current Service Descriptor Table (SDT) in devicephysicalmemory with the original SDT found in ntoskrnl.exe.  Assigned (20050821)  None (candidate not yet proposed)    View
10902  CVE-2004-2476  Candidate  Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop and crash) via an IFRAME with "?" as the file source.  Assigned (20050820)  None (candidate not yet proposed)    View
10901  CVE-2004-2475  Candidate  Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the About section. NOTE: some followup posts suggest that the demonstration code"s use of the res:// protocol does not cross privilege boundaries, since it is not allowed in the Internet Zone. Thus this might not be a vulnerability.  Assigned (20050820)  None (candidate not yet proposed)    View

Page 18763 of 20943, showing 5 records out of 104715 total, starting on record 93811, ending on 93815

Actions