CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10605  CVE-2004-2179  Candidate  asycpict.dll, as used in Microsoft products such as Front Page 97 and 98, allows remote attackers to cause a denial of service (hang) via a JPEG image with maximum height and width values.  Assigned (20050711)  None (candidate not yet proposed)    View
10606  CVE-2004-2180  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in WowBB Forum 1.61 allow remote attackers to inject arbitrary web script or HTML via the (1) country parameter to view_user.php, (2) show parameter to view_forum.php, (3) letter parameter to view_user.php, (4) highlight parameter to view_topic.php, (5) show parameter to index.php, (6) q parameter to search.php, (7) Referer header to admin.php, or the (8) user_email parameter to login.php.  Assigned (20050711)  None (candidate not yet proposed)    View
10607  CVE-2004-2181  Candidate  Multiple SQL injection vulnerabilities in WowBB Forum 1.61 allow remote attackers to execute arbitrary SQL commands via the (1) sort_by or (2) page parameters to view_user.php, or the (3) forum_id parameter to view_topic.php. NOTE: the sort_by vector was later reported to be present in WowBB 1.65.  Assigned (20050711)  REVIEWING(1) Christey  Christey> The view_user.php/sort_by vector is covered by several CVEs. | Need to figure out how to handle this.  View
10608  CVE-2004-2182  Candidate  Session fixation vulnerability in Macromedia JRun 4.0 allows remote attackers to hijack user sessions by pre-setting the user session ID information used by the session server.  Assigned (20050711)  None (candidate not yet proposed)    View
10609  CVE-2004-2183  Candidate  Unknown vulnerability in WeHelpBUS 0.1 allows remote attackers to execute arbitrary shell commands via the query string.  Assigned (20050711)  None (candidate not yet proposed)    View

Page 19152 of 20943, showing 5 records out of 104715 total, starting on record 95756, ending on 95760

Actions