CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8620  CVE-2004-0192  Candidate  Cross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote attackers to steal cookies and hijack a management session via a /sgmi URL that contains malicious script, which is not quoted in the resulting error page.  Modified (20040813)  ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall    View
8619  CVE-2004-0191  Entry  Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events.        View
8618  CVE-2004-0190  Entry  Symantec FireWall/VPN Appliance model 200 records a cleartext password for the password administration page, which may be cached on the administrator"s local system or in a proxy, which allows attackers to steal the password and gain privileges.        View
8617  CVE-2004-0189  Entry  The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") character, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.        View
8616  CVE-2004-0188  Entry  Heap-based buffer overflow in Calife 2.8.5 and earlier may allow local users to execute arbitrary code via a long password.        View

Page 19220 of 20943, showing 5 records out of 104715 total, starting on record 96096, ending on 96100

Actions