CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10080 | CVE-2004-1652 | Candidate | phpScheduleIt 1.0.0 RC1 does not clear administrative privileges if the administrator logs in as a normal user, which allows users with physical access to gain administrative privileges. | Assigned (20050221) | None (candidate not yet proposed) | View | |
10079 | CVE-2004-1651 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in the registration page in phpScheduleIt 1.0.0 RC1 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Lastname fields during new user registration, or (3) the Schedule Name field. | Assigned (20050221) | None (candidate not yet proposed) | View | |
10078 | CVE-2004-1650 | Candidate | D-Link DCS-900 Internet Camera listens on UDP port 62976 for an IP address, which allows remote attackers to change the IP address of the camera via a UDP broadcast packet. | Assigned (20050221) | None (candidate not yet proposed) | View | |
10077 | CVE-2004-1649 | Candidate | Buffer overflow in Microsoft Msinfo32.exe might allow local users to execute arbitrary code via a long filename in the msinfo_file command line parameter. NOTE: this issue might not cross security boundaries, so it may be REJECTED in the future. | Assigned (20050221) | None (candidate not yet proposed) | View | |
10076 | CVE-2004-1648 | Candidate | Cross-site scripting (XSS) vulnerability in (1) index.asp, (2) ChangePassword.asp, (3) users_list.asp, (4) and users_add.asp in Password Protect allows remote attackers to inject arbitrary web script or HTML via the ShowMsg parameter. | Assigned (20050221) | None (candidate not yet proposed) | View |
Page 18928 of 20943, showing 5 records out of 104715 total, starting on record 94636, ending on 94640