CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10830  CVE-2004-2404  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-2347. Reason: This candidate is a duplicate of CVE-2004-2347. Notes: All CVE users should reference CVE-2004-2347 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20050817)  None (candidate not yet proposed)    View
10829  CVE-2004-2403  Candidate  Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the administrative user via a link or IMG tag to YaBB.pl that specifies the desired action, id, and moda parameters.  Assigned (20050817)  None (candidate not yet proposed)    View
10828  CVE-2004-2402  Candidate  Cross-site scripting (XSS) vulnerability in YaBB.pl in YaBB 1 GOLD SP 1.3.2 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded to parameter. NOTE: some sources say that the board parameter is affected, but this is incorrect.  Assigned (20050817)  None (candidate not yet proposed)    View
10827  CVE-2004-2401  Candidate  Stack-based buffer overflow in Ipswitch IMail Express Web Messaging before 8.05 might allow remote attackers to execute arbitrary code via an HTML message with long "tag text."  Assigned (20050817)  None (candidate not yet proposed)    View
10826  CVE-2004-2400  Candidate  WinFTP Server 1.6 stores username and password credentials in plaintext in the datauser.wfd file, which allows local users to gain access to the credentials.  Assigned (20050817)  None (candidate not yet proposed)    View

Page 18778 of 20943, showing 5 records out of 104715 total, starting on record 93886, ending on 93890

Actions