CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10690  CVE-2004-2264  Candidate  ** DISPUTED ** Format string bug in the open_altfile function in filename.c for GNU less 382, 381, and 358 might allow local users to cause a denial of service or possibly execute arbitrary code via format strings in the LESSOPEN environment variable. NOTE: since less is not setuid or setgid, then this is not a vulnerability unless there are plausible scenarios under which privilege boundaries could be crossed.  Assigned (20050719)  None (candidate not yet proposed)    View
10689  CVE-2004-2263  Candidate  SQL injection vulnerability in the valid function in fr_left.php in PlaySMS 0.7 and earlier allows remote attackers to modify SQL statements via the vc2 cookie.  Assigned (20050719)  None (candidate not yet proposed)    View
10688  CVE-2004-2262  Candidate  ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php.  Assigned (20050719)  None (candidate not yet proposed)    View
10687  CVE-2004-2261  Candidate  Cross-site scripting (XSS) vulnerability in e107 allows remote attackers to inject arbitrary script or HTML via the "login name/author" field in the (1) news submit or (2) article submit functions.  Assigned (20050719)  None (candidate not yet proposed)    View
10686  CVE-2004-2260  Candidate  Opera Browser 7.23, and other versions before 7.50, updates the address bar as soon as the user clicks a link, which allows remote attackers to redirect to other sites via the onUnload attribute.  Assigned (20050719)  None (candidate not yet proposed)    View

Page 18806 of 20943, showing 5 records out of 104715 total, starting on record 94026, ending on 94030

Actions