CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10495  CVE-2004-2069  Candidate  sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly signal the non-privileged process when a session has been terminated after exceeding the LoginGraceTime setting, which leaves the connection open and allows remote attackers to cause a denial of service (connection consumption).  Assigned (20050505)  None (candidate not yet proposed)    View
10494  CVE-2004-2068  Candidate  fetchnews in leafnode 1.9.47 and earlier allows remote attackers to cause a denial of service (process hang) via an emptry NNTP news article with missing mandatory headers.  Assigned (20050505)  None (candidate not yet proposed)    View
10493  CVE-2004-2067  Candidate  SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) password, or (3) crypted_password parameters.  Assigned (20050504)  None (candidate not yet proposed)    View
10492  CVE-2004-2066  Candidate  SQL injection vulnerability in session.php in LinPHA 0.9.4 allows remote attackers to execute arbitrary SQL code and bypass authentication via the (1) linpha_userid or (2) linpha_password cookies.  Assigned (20050504)  None (candidate not yet proposed)    View
10491  CVE-2004-2065  Candidate  DansGuardian 2.8 and earlier allows remote attackers to bypass the extension filtering rule via a hex encoded extension or . in the filename.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 18845 of 20943, showing 5 records out of 104715 total, starting on record 94221, ending on 94225

Actions