CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9750  CVE-2004-1322  Candidate  Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages.  Assigned (20050106)  None (candidate not yet proposed)    View
9749  CVE-2004-1321  Candidate  The configuration backup in Asante FM2008 running firmware 1.06 stores the username and password in cleartext, which could allow remote attackers to gain unauthorized access.  Assigned (20050106)  None (candidate not yet proposed)    View
9748  CVE-2004-1320  Candidate  Asante FM2008 running firmware 1.06 is shipped with a default username and password, which could allow remote attackers to gain unauthorized access.  Assigned (20050106)  None (candidate not yet proposed)    View
9747  CVE-2004-1319  Candidate  The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by "AbusiveParent" in Internet Explorer 6.0.2900.2180.  Assigned (20050106)  None (candidate not yet proposed)    View
9746  CVE-2004-1318  Candidate  Cross-site scripting (XSS) vulnerability in namazu.cgi for Namazu 2.0.13 and earlier allows remote attackers to inject arbitrary HTML and web script via a query that starts with a tab ("%09") character, which prevents the rest of the query from being properly sanitized.  Assigned (20050103)  None (candidate not yet proposed)    View

Page 18994 of 20943, showing 5 records out of 104715 total, starting on record 94966, ending on 94970

Actions