CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9935 | CVE-2004-1507 | Candidate | CRLF injection vulnerability in login.php in WebCalendar allows remote attackers to inject CRLF sequences via the return_path parameter and perform HTTP Response Splitting attacks to modify expected HTML content from the server. | Assigned (20050218) | None (candidate not yet proposed) | View | |
9934 | CVE-2004-1506 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar allow remote attackers to inject arbitrary web script via (1) view_entry.php, (2) view_d.php, (3) usersel.php, (4) datesel.php, (5) trailer.php, or (6) styles.php, as demonstrated using img srg tags. | Assigned (20050218) | None (candidate not yet proposed) | View | |
9933 | CVE-2004-1505 | Candidate | Directory traversal vulnerability in index.php in Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to read arbitrary files and possibly execute PHP code via a .. (dot dot) in the show parameter. | Assigned (20050218) | None (candidate not yet proposed) | View | |
9932 | CVE-2004-1504 | Candidate | The displaycontent function in config.php for Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to gain sensitive information via a blank show parameter, which reveals the installation path in an error message, as demonstrated using index.php. | Assigned (20050218) | None (candidate not yet proposed) | View | |
9931 | CVE-2004-1503 | Candidate | Integer overflow in the InitialDirContext in Java Runtime Environment (JRE) 1.4.2, 1.5.0 and possibly other versions allows remote attackers to cause a denial of service (Java exception and failed DNS requests) via a large number of DNS requests, which causes the xid variable to wrap around and become negative. | Assigned (20050218) | None (candidate not yet proposed) | View |
Page 18957 of 20943, showing 5 records out of 104715 total, starting on record 94781, ending on 94785