CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8750 | CVE-2004-0322 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to execute arbitrary script as other users via the (1) member parameter in member.php, (2) uid parameter in u2uadmin.php, (3) user parameter in editprofile.php, (4) an onmouseover event in an align tag when bbcode is allowed, or (5) img tag where bbcode is allowed. | Modified (20050718) | ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall | View | |
8749 | CVE-2004-0321 | Candidate | Team Factor 1.25 and earlier allows remote attackers to cause a denial of service (crash) via a packet that uses a negative number to specify the size of the data block that follows, which causes Team Factor to read unallocated memory. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8748 | CVE-2004-0320 | Entry | Unknown vulnerability in nCipher Hardware Security Modules (HSM) 1.67.x through 1.99.x allows local users to access secrets stored in the module"s run-time memory via certain sequences of commands. | View | |||
8747 | CVE-2004-0319 | Candidate | Cross-site scripting (XSS) vulnerability in the font tag in ezBoard 7.3u allows remote attackers to execute arbitrary script as other users, as demonstrated using the background:url in a (1) font color or (2) font face argument. | Proposed (20040318) | ACCEPT(2) Armstrong, Cole | NOOP(3) Balinsky, Cox, Wall | View | |
8746 | CVE-2004-0318 | Candidate | Load Sharing Facility (LSF) 4.x, 5.x, and 6.x uses the LSF_EAUTH_UID environment variable, if it exists, instead of the real UID of the user, which could allow remote attackers within the local cluster to gain privileges. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View |
Page 19194 of 20943, showing 5 records out of 104715 total, starting on record 95966, ending on 95970