CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10913  CVE-2004-2487  Candidate  Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via (1) "..", (2) ".." (backslash dot dot), or (3) "/../" sequences in (a) RETR (get), (b) NLST (ls), (c) LIST (ls), (d) RNFR, or (e) RNTO FTP commands.  Assigned (20051025)  None (candidate not yet proposed)    View
10914  CVE-2004-2488  Candidate  Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via "C:" sequences in the (1) RETR (get), (2) NLST (ls), (3) LIST (ls), (4) RNFR, or (5) RNTO FTP commands.  Assigned (20051025)  None (candidate not yet proposed)    View
10915  CVE-2004-2489  Candidate  Format string vulnerability in IBM Informix Dynamic Server (IDS) before 9.40.xC3 allows local users to execute arbitrary code via a modified INFORMIXDIR environment variable that points to a file with format string specifiers in the filename.  Assigned (20051025)  None (candidate not yet proposed)    View
10916  CVE-2004-2490  Candidate  Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.xC1 and 9.40.xC2 allows local users to execute arbitrary code via a long GL_PATH environment variable.  Assigned (20051025)  None (candidate not yet proposed)    View
10917  CVE-2004-2491  Candidate  A race condition in Opera web browser 7.53 Build 3850 causes Opera to fill in the address bar before the page has been loaded, which allows remote attackers to spoof the URL in the address bar via the window.open and location.replace HTML parameters, which facilitates phishing attacks.  Assigned (20051025)  None (candidate not yet proposed)    View

Page 18817 of 20943, showing 5 records out of 104715 total, starting on record 94081, ending on 94085

Actions