CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9105 | CVE-2004-0677 | Candidate | Fastream NETFile FTP Server 6.7.2.1085 and earlier allows remote attackers to cause a denial of service (temporary hang) via the cd command with an unusual argument, possibly due to multiple leading slashes and/or an access to the floppy drive ("A"). | Assigned (20040712) | None (candidate not yet proposed) | View | |
9104 | CVE-2004-0676 | Candidate | Directory traversal vulnerability in Fastream NETFile FTP/Web Server 6.7.2.1085 and earlier allows remote attackers to create or delete arbitrary files via .. (dot dot) and // (double slash) sequences in the filename parameter. | Assigned (20040712) | None (candidate not yet proposed) | View | |
9103 | CVE-2004-0675 | Candidate | Cross-site scripting (XSS) vulnerability in (1) cart32.exe or (2) c32web.exe in Cart32 shopping cart allows remote attackers to execute arbitrary web script via the cart32 parameter to a GetLatestBuilds command. | Assigned (20040712) | None (candidate not yet proposed) | View | |
9102 | CVE-2004-0674 | Candidate | Enterasys XSR-1800 series Security Routers, when running firmware 7.0.0.0 and using Policy-Based Routing, allow remote attackers to cause a denial of service (crash) via a packet with the IP record route option set. | Assigned (20040712) | None (candidate not yet proposed) | View | |
9101 | CVE-2004-0673 | Candidate | Cross-site scripting (XSS) vulnerability in SCI Photo Chat Server 3.4.9 allows remote attackers to execute arbitrary web script as other users via an invalid request that is echoed in the resulting error message. | Assigned (20040712) | None (candidate not yet proposed) | View |
Page 19123 of 20943, showing 5 records out of 104715 total, starting on record 95611, ending on 95615