CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8620 | CVE-2004-0192 | Candidate | Cross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote attackers to steal cookies and hijack a management session via a /sgmi URL that contains malicious script, which is not quoted in the resulting error page. | Modified (20040813) | ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall | View | |
8619 | CVE-2004-0191 | Entry | Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events. | View | |||
8618 | CVE-2004-0190 | Entry | Symantec FireWall/VPN Appliance model 200 records a cleartext password for the password administration page, which may be cached on the administrator"s local system or in a proxy, which allows attackers to steal the password and gain privileges. | View | |||
8617 | CVE-2004-0189 | Entry | The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") character, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists. | View | |||
8616 | CVE-2004-0188 | Entry | Heap-based buffer overflow in Calife 2.8.5 and earlier may allow local users to execute arbitrary code via a long password. | View |
Page 19220 of 20943, showing 5 records out of 104715 total, starting on record 96096, ending on 96100