CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8770 | CVE-2004-0342 | Candidate | WFTPD Pro Server 3.21 Release 1, with the XeroxDocutech option enabled, allows local users to cause a denial of service (crash) via a (1) MKD or (2) XMKD command that causes an absolute path of 260 characters to be used, which overwrites a cookie with a null character, possibly due to an off-by-one error. | Modified (20050718) | ACCEPT(2) Armstrong, Wall | NOOP(2) Cole, Cox | View | |
8769 | CVE-2004-0341 | Candidate | WFTPD Pro Server 3.21 Release 1 allocates memory for a command until a 0Ah byte (newline) is sent, which allows local users to cause a denial of service (CPU consumption) by continuing to send a long command that does not contain a newline. | Modified (20050719) | ACCEPT(2) Armstrong, Wall | NOOP(2) Cole, Cox | View | |
8768 | CVE-2004-0340 | Candidate | Stack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Server 3.10 allows local users to execute arbitrary code via long (1) LIST, (2) NLST, or (3) STAT commands. | Modified (20050719) | ACCEPT(2) Armstrong, Wall | NOOP(2) Cole, Cox | View | |
8767 | CVE-2004-0339 | Candidate | Cross-site scripting (XSS) vulnerability in ViewTopic.php in phpBB, possibly 2.0.6c and earlier, allows remote attackers to execute arbitrary script or HTML as other users via the postorder parameter. | Proposed (20040318) | ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall | View | |
8766 | CVE-2004-0338 | Candidate | SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL queries via the st parameter. | Proposed (20040318) | ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall | View |
Page 19190 of 20943, showing 5 records out of 104715 total, starting on record 95946, ending on 95950