CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10571 | CVE-2004-2145 | Candidate | SQL injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows remote attackers to execute arbitrary SQL commands via the (1) sortdir or (2) criteria parameter to ladder-log.asp or the (3) memberid or (4) teamid parameter to view-profile.asp. | Assigned (20050701) | None (candidate not yet proposed) | View | |
10572 | CVE-2004-2146 | Candidate | CRLF injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows attackers to conduct HTTP response splitting attacks via the fid parameter in a writenew action to thread-post.asp. | Assigned (20050701) | None (candidate not yet proposed) | View | |
10573 | CVE-2004-2147 | Candidate | Unknown versions of Symantec Norton AntiVirus and Microsoft Outlook allow attackers to cause a denial of service (crash) via malformed e-mail messages (1) without a body or (2) without a carriage return (" ") separating the headers from the body. | Assigned (20050701) | None (candidate not yet proposed) | View | |
10574 | CVE-2004-2148 | Candidate | Unknown local vulnerability in the "change user" feature of Slava Astashonok Fprobe 1.0.5 and earlier has unknown impact and attack vectors. | Assigned (20050701) | None (candidate not yet proposed) | View | |
10575 | CVE-2004-2149 | Candidate | Buffer overflow in the prepared statements API in libmysqlclient for MySQL 4.1.3 beta and 4.1.4 allows remote attackers to cause a denial of service via a large number of placeholders. | Assigned (20050701) | None (candidate not yet proposed) | View |
Page 19181 of 20943, showing 5 records out of 104715 total, starting on record 95901, ending on 95905