CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8780  CVE-2004-0352  Candidate  Cisco 11000 Series Content Services Switches (CSS) running WebNS 5.0(x) before 05.0(04.07)S, and 6.10(x) before 06.10(02.05)S allow remote attackers to cause a denial of service (device reset) via a malformed packet to UDP port 5002.  Proposed (20040318)  ACCEPT(4) Armstrong, Baker, Cole, Wall | NOOP(2) Christey, Cox  Christey> According to the Details section of the advisory, the | vulnerability can only be exploited through the management port, which | is "available solely through the physical management interface." So, | change the description to point out that physical access is required. | Thanks to esCERT-UPC for pointing this out.  View
8779  CVE-2004-0351  Candidate  Spider Sales shopping cart stores the private key in the same database and table as the public key, which allows local users with access to the database to decrypt data.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View
8778  CVE-2004-0350  Candidate  SpiderSales shopping cart does not enforce a minimum length for the private key, which can make it easier for local users to obtain the private key by factoring.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View
8777  CVE-2004-0349  Candidate  Directory traversal vulnerability in GWeb HTTP Server 0.6 allows remote attackers to view arbitrary files via a .. (dot dot) in the URL.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8776  CVE-2004-0348  Candidate  SQL injection vulnerability in viewCart.asp in SpiderSales shopping cart software allows remote attackers to execute arbitrary SQL via the userId parameter.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View

Page 19188 of 20943, showing 5 records out of 104715 total, starting on record 95936, ending on 95940

Actions