CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8965  CVE-2004-0537  Candidate  Opera 7.50 and earlier allows remote web sites to provide a "Shortcut Icon" (favicon) that is wider than expected, which could allow the web sites to spoof a trusted domain and facilitate phishing attacks using a wide icon and extra spaces.  Assigned (20040604)  None (candidate not yet proposed)    View
8964  CVE-2004-0536  Candidate  Format string vulnerability in Tripwire commercial 4.0.1 and earlier, including 2.4, and open source 2.3.1 and earlier, allows local users to gain privileges via format string specifiers in a file name, which is used in the generation of an email report.  Assigned (20040604)  None (candidate not yet proposed)    View
8963  CVE-2004-0535  Candidate  The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this issue was originally incorrectly reported as a "buffer overflow" by some sources.  Assigned (20040604)  None (candidate not yet proposed)    View
8962  CVE-2004-0534  Candidate  Cross-site scripting (XSS) vulnerability in Business Objects InfoView 5.1.4 through 5.1.8 for WebIntelligence 2.7.0 through 2.7.4 allows remote attackers to inject arbitrary web script or HTML via document names when uploading a document.  Assigned (20040604)  None (candidate not yet proposed)    View
8961  CVE-2004-0533  Candidate  Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users to delete arbitrary files on the server via a crafted delete request using the InfoView web client.  Assigned (20040604)  None (candidate not yet proposed)    View

Page 19151 of 20943, showing 5 records out of 104715 total, starting on record 95751, ending on 95755

Actions