CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10560  CVE-2004-2134  Candidate  Oracle toplink mapping workBench uses a weak encryption algorithm for passwords, which allows local users to decrypt the passwords.  Assigned (20050527)  None (candidate not yet proposed)    View
10559  CVE-2004-2133  Candidate  Certain third-party packages for CVSup 16.1h, such as SuSE Linux, contain untrusted paths in the ELF RPATH fields of certain executables, which could allow local users to execute arbitrary code by causing cvsup to link against malicious libraries that are created in world-writable directories such as /usr/src/packages.  Assigned (20050527)  None (candidate not yet proposed)    View
10558  CVE-2004-2132  Candidate  Directory traversal vulnerability in PJreview_Neo.cgi in PJ CGI Neo review allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter.  Assigned (20050527)  None (candidate not yet proposed)    View
10557  CVE-2004-2131  Candidate  Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, with DSA privileges, to execute arbitrary code via a long ONCONFIG environment variable.  Assigned (20050527)  None (candidate not yet proposed)    View
10556  CVE-2004-2130  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in privmsg.php in phpBB 2.0.6 allow remote attackers to execute arbitrary script or HTML via the (1) folder or (2) mode variables.  Assigned (20050527)  None (candidate not yet proposed)    View

Page 18832 of 20943, showing 5 records out of 104715 total, starting on record 94156, ending on 94160

Actions