CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8750  CVE-2004-0322  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to execute arbitrary script as other users via the (1) member parameter in member.php, (2) uid parameter in u2uadmin.php, (3) user parameter in editprofile.php, (4) an onmouseover event in an align tag when bbcode is allowed, or (5) img tag where bbcode is allowed.  Modified (20050718)  ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall    View
8749  CVE-2004-0321  Candidate  Team Factor 1.25 and earlier allows remote attackers to cause a denial of service (crash) via a packet that uses a negative number to specify the size of the data block that follows, which causes Team Factor to read unallocated memory.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8748  CVE-2004-0320  Entry  Unknown vulnerability in nCipher Hardware Security Modules (HSM) 1.67.x through 1.99.x allows local users to access secrets stored in the module"s run-time memory via certain sequences of commands.        View
8747  CVE-2004-0319  Candidate  Cross-site scripting (XSS) vulnerability in the font tag in ezBoard 7.3u allows remote attackers to execute arbitrary script as other users, as demonstrated using the background:url in a (1) font color or (2) font face argument.  Proposed (20040318)  ACCEPT(2) Armstrong, Cole | NOOP(3) Balinsky, Cox, Wall    View
8746  CVE-2004-0318  Candidate  Load Sharing Facility (LSF) 4.x, 5.x, and 6.x uses the LSF_EAUTH_UID environment variable, if it exists, instead of the real UID of the user, which could allow remote attackers within the local cluster to gain privileges.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View

Page 19194 of 20943, showing 5 records out of 104715 total, starting on record 95966, ending on 95970

Actions