CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10520 | CVE-2004-2094 | Candidate | Cross-site scripting (XSS) vulnerability in WebcamXP 1.06.945 allows remote attackers to inject arbitrary HTML or web script as other users via a URL that contains the script. | Assigned (20050527) | None (candidate not yet proposed) | View | |
10519 | CVE-2004-2093 | Candidate | Buffer overflow in the open_socket_out function in socket.c for rsync 2.5.7 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long RSYNC_PROXY environment variable. NOTE: since rsync is not setuid, this issue does not provide any additional privileges beyond those that are already available to the user. Therefore this issue may be REJECTED in the future. | Assigned (20050519) | None (candidate not yet proposed) | View | |
10518 | CVE-2004-2092 | Candidate | eTrust InoculateIT for Linux 6.0 uses insecure permissions for multiple files and directories, including the application"s registry and tmp directories, which allows local users to delete, modify, or examine sensitive information. | Assigned (20050519) | None (candidate not yet proposed) | View | |
10517 | CVE-2004-2091 | Candidate | Microsoft Baseline Security Analyzer (MBSA) 1.2 does not correctly identify systems that have been patched but remain vulnerable to exploit until the system is rebooted, possibly giving the administrator a false sense of security. | Assigned (20050519) | None (candidate not yet proposed) | View | |
10516 | CVE-2004-2090 | Candidate | Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture method, which returns an error code if the file does not exist. | Assigned (20050519) | None (candidate not yet proposed) | View |
Page 18840 of 20943, showing 5 records out of 104715 total, starting on record 94196, ending on 94200