CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10590  CVE-2004-2164  Candidate  shoprestoreorder.asp in VP-ASP 5.0 does not close the database connection when a user restores a previous order, which allows remote attackers to cause a denial of service (connection consumption).  Assigned (20050710)  None (candidate not yet proposed)    View
10589  CVE-2004-2163  Candidate  login_radius on OpenBSD 3.2, 3.5, and possibly other versions does not verify the shared secret in a response packet from a RADIUS server, which allows remote attackers to bypass authentication by spoofing server replies.  Assigned (20050710)  None (candidate not yet proposed)    View
10588  CVE-2004-2162  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the search field of the Address Module or (2) the t parameter to app_new.php.  Assigned (20050710)  None (candidate not yet proposed)    View
10587  CVE-2004-2161  Candidate  SQL injection vulnerability in file_overview.php in TUTOS 1.1 allows remote attackers to execute arbitrary SQL commands via the link_id parameter.  Assigned (20050710)  None (candidate not yet proposed)    View
10586  CVE-2004-2160  Candidate  Format string vulnerability in xml_elem.c for XMLStarlet Command Line XML Toolkit 0.9.3 may allow attackers to cause a denial of service or execute arbitrary code.  Assigned (20050710)  None (candidate not yet proposed)    View

Page 18826 of 20943, showing 5 records out of 104715 total, starting on record 94126, ending on 94130

Actions