CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10571  CVE-2004-2145  Candidate  SQL injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows remote attackers to execute arbitrary SQL commands via the (1) sortdir or (2) criteria parameter to ladder-log.asp or the (3) memberid or (4) teamid parameter to view-profile.asp.  Assigned (20050701)  None (candidate not yet proposed)    View
10572  CVE-2004-2146  Candidate  CRLF injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows attackers to conduct HTTP response splitting attacks via the fid parameter in a writenew action to thread-post.asp.  Assigned (20050701)  None (candidate not yet proposed)    View
10573  CVE-2004-2147  Candidate  Unknown versions of Symantec Norton AntiVirus and Microsoft Outlook allow attackers to cause a denial of service (crash) via malformed e-mail messages (1) without a body or (2) without a carriage return (" ") separating the headers from the body.  Assigned (20050701)  None (candidate not yet proposed)    View
10574  CVE-2004-2148  Candidate  Unknown local vulnerability in the "change user" feature of Slava Astashonok Fprobe 1.0.5 and earlier has unknown impact and attack vectors.  Assigned (20050701)  None (candidate not yet proposed)    View
10575  CVE-2004-2149  Candidate  Buffer overflow in the prepared statements API in libmysqlclient for MySQL 4.1.3 beta and 4.1.4 allows remote attackers to cause a denial of service via a large number of placeholders.  Assigned (20050701)  None (candidate not yet proposed)    View

Page 19181 of 20943, showing 5 records out of 104715 total, starting on record 95901, ending on 95905

Actions