CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10340  CVE-2004-1913  Candidate  Cross-site scripting (XSS) vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to inject arbitrary web script or HTML via the eid parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10339  CVE-2004-1912  Candidate  The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalendar 1.1.a, as used in PHP-Nuke, allow remote attackers to obtain sensitive information via a URL with an invalid argument, which reveals the full path in an error message.  Assigned (20050504)  None (candidate not yet proposed)    View
10338  CVE-2004-1911  Candidate  Cross-site scripting (XSS) vulnerability in AzDGDatingLite 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) l parameter (aka language variable) to index.php or (2) id parameter to view.php.  Assigned (20050504)  None (candidate not yet proposed)    View
10337  CVE-2004-1910  Candidate  rufsi.dll in Symantec Virus Detection allows remote attackers to cause a denial of service (crash) via a long string to the GetPrivateProfileString function. NOTE: this issue was originally reported as a buffer overflow, but that specific claim is disputed by the vendor, although a crash is acknowledged.  Assigned (20050504)  None (candidate not yet proposed)    View
10336  CVE-2004-1909  Candidate  Claim Anti-Virus (ClamAV) 0.68 and earlier allows remote attackers to cause a denial of service (crash) via certain RAR archives, such as those generated by the Beagle/Bagle worm.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 18876 of 20943, showing 5 records out of 104715 total, starting on record 94376, ending on 94380

Actions