CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10680  CVE-2004-2254  Candidate  SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration interface via a direct request to admin.cgi with a modified utoken parameter.  Assigned (20050717)  None (candidate not yet proposed)    View
10679  CVE-2004-2253  Candidate  Directory traversal vulnerability in user.cgi in SurgeLDAP 1.0g and earlier allows remote attackers to read arbitrary files via a .. in the page parameter of the show command.  Assigned (20050717)  None (candidate not yet proposed)    View
10678  CVE-2004-2252  Candidate  The firewall in Astaro Security Linux before 4.024 sends responses to SYN-FIN packets, which makes it easier for remote attackers to obtain information about the system and construct specialized attacks.  Assigned (20050717)  None (candidate not yet proposed)    View
10677  CVE-2004-2251  Candidate  The PPTP server in Astaro Security Linux before 4.024 provides information about its version, which makes it easier for remote attackers to construct specialized attacks.  Assigned (20050717)  None (candidate not yet proposed)    View
10676  CVE-2004-2250  Candidate  Unknown vulnerability in the "access code" in RemoteEditor before 0.1.6 has unknown impact and attack vectors, possibly involving a bypass of IP address restrictions.  Assigned (20050717)  None (candidate not yet proposed)    View

Page 18808 of 20943, showing 5 records out of 104715 total, starting on record 94036, ending on 94040

Actions