CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9090 | CVE-2004-0662 | Candidate | PowerPortal 1.x allows remote attackers to gain sensitive information via invalid or missing parameters in HTTP requests to (1) resize.php or (2) modules.php, which reveals the path in an error message. | Assigned (20040712) | None (candidate not yet proposed) | View | |
9089 | CVE-2004-0661 | Candidate | Integer signedness error in D-Link AirPlus DI-614+ running firmware 2.30 and earlier allows remote attackers to cause a denial of service (IP lease depletion) via a DHCP request with the LEASETIME option set to -1, which makes the DHCP lease valid for thirteen or more years. | Assigned (20040712) | None (candidate not yet proposed) | View | |
9088 | CVE-2004-0660 | Candidate | Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in CuteNews 1.3.1 allows remote attackers to inject arbitrary script or HTML via the id parameter. | Assigned (20040712) | None (candidate not yet proposed) | View | |
9087 | CVE-2004-0659 | Candidate | Buffer overflow in TranslateFilename for common.c in MPlayer 1.0pre4 allows remote attackers to execute arbitrary code via a long file name. | Assigned (20040712) | None (candidate not yet proposed) | View | |
9086 | CVE-2004-0658 | Candidate | Integer overflow in the hpsb_alloc_packet function (incorrectly reported as alloc_hpsb_packet) in IEEE 1394 (Firewire) driver 2.4 and 2.6 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via the functions (1) raw1394_write, (2) state_connected, (3) handle_remote_request, or (4) hpsb_make_writebpacket. | Assigned (20040712) | None (candidate not yet proposed) | View |
Page 19126 of 20943, showing 5 records out of 104715 total, starting on record 95626, ending on 95630