CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10495 | CVE-2004-2069 | Candidate | sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly signal the non-privileged process when a session has been terminated after exceeding the LoginGraceTime setting, which leaves the connection open and allows remote attackers to cause a denial of service (connection consumption). | Assigned (20050505) | None (candidate not yet proposed) | View | |
10494 | CVE-2004-2068 | Candidate | fetchnews in leafnode 1.9.47 and earlier allows remote attackers to cause a denial of service (process hang) via an emptry NNTP news article with missing mandatory headers. | Assigned (20050505) | None (candidate not yet proposed) | View | |
10493 | CVE-2004-2067 | Candidate | SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) password, or (3) crypted_password parameters. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10492 | CVE-2004-2066 | Candidate | SQL injection vulnerability in session.php in LinPHA 0.9.4 allows remote attackers to execute arbitrary SQL code and bypass authentication via the (1) linpha_userid or (2) linpha_password cookies. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10491 | CVE-2004-2065 | Candidate | DansGuardian 2.8 and earlier allows remote attackers to bypass the extension filtering rule via a hex encoded extension or . in the filename. | Assigned (20050504) | None (candidate not yet proposed) | View |
Page 18845 of 20943, showing 5 records out of 104715 total, starting on record 94221, ending on 94225