CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10080  CVE-2004-1652  Candidate  phpScheduleIt 1.0.0 RC1 does not clear administrative privileges if the administrator logs in as a normal user, which allows users with physical access to gain administrative privileges.  Assigned (20050221)  None (candidate not yet proposed)    View
10079  CVE-2004-1651  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the registration page in phpScheduleIt 1.0.0 RC1 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Lastname fields during new user registration, or (3) the Schedule Name field.  Assigned (20050221)  None (candidate not yet proposed)    View
10078  CVE-2004-1650  Candidate  D-Link DCS-900 Internet Camera listens on UDP port 62976 for an IP address, which allows remote attackers to change the IP address of the camera via a UDP broadcast packet.  Assigned (20050221)  None (candidate not yet proposed)    View
10077  CVE-2004-1649  Candidate  Buffer overflow in Microsoft Msinfo32.exe might allow local users to execute arbitrary code via a long filename in the msinfo_file command line parameter. NOTE: this issue might not cross security boundaries, so it may be REJECTED in the future.  Assigned (20050221)  None (candidate not yet proposed)    View
10076  CVE-2004-1648  Candidate  Cross-site scripting (XSS) vulnerability in (1) index.asp, (2) ChangePassword.asp, (3) users_list.asp, (4) and users_add.asp in Password Protect allows remote attackers to inject arbitrary web script or HTML via the ShowMsg parameter.  Assigned (20050221)  None (candidate not yet proposed)    View

Page 18928 of 20943, showing 5 records out of 104715 total, starting on record 94636, ending on 94640

Actions