CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10899  CVE-2004-2473  Candidate  wmFrog weather monitor 0.1.6 and other versions before 0.2.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.  Assigned (20050820)  None (candidate not yet proposed)    View
10900  CVE-2004-2474  Candidate  SQL injection vulnerability in PHPNews 1.2.3 allows remote attackers to execute arbitrary SQL commands via the mid parameter to sendtofriend.php.  Assigned (20050820)  None (candidate not yet proposed)    View
10901  CVE-2004-2475  Candidate  Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the About section. NOTE: some followup posts suggest that the demonstration code"s use of the res:// protocol does not cross privilege boundaries, since it is not allowed in the Internet Zone. Thus this might not be a vulnerability.  Assigned (20050820)  None (candidate not yet proposed)    View
10902  CVE-2004-2476  Candidate  Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop and crash) via an IFRAME with "?" as the file source.  Assigned (20050820)  None (candidate not yet proposed)    View
13827  CVE-2005-2621  Candidate  index.php in ECW-Shop 6.0.2 allows remote attackers to obtain sensitive information via the (1) min or (2) max parameter with a """ (single quote), which reveals the path in an error message, possibly due to a SQL injection vulnerability.  Assigned (20050819)  None (candidate not yet proposed)    View

Page 18972 of 20943, showing 5 records out of 104715 total, starting on record 94856, ending on 94860

Actions