CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8445  CVE-2004-0017  Candidate  Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to perform unauthorized database operations.  Modified (20071113)  ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Williams | NOOP(2) Cox, Wall  Williams> i believe this affects phpGroupWare 0.9.14.006 and earlier, and phpGroupWare 0.9.16RC1 and earlier. | http://phpgroupware.org/downloads  View
8444  CVE-2004-0016  Entry  The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers to create and execute PHP files.        View
8443  CVE-2004-0015  Entry  vbox3 0.1.8 and earlier does not properly drop privileges before executing a user-provided TCL script, which allows local users to gain privileges.        View
8442  CVE-2004-0014  Candidate  Multiple buffer overflows in the nd WebDAV interface 0.8.2 and earlier allows remote web servers to execute arbitrary code via certain long strings.  Modified (20071113)  ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Williams | NOOP(2) Cox, Wall  Williams> need to change desc. i think this was fixed in 0.8.2. | http://www.gohome.org/nd  View
8441  CVE-2004-0013  Entry  jabber 1.4.2, 1.4.2a, and possibly earlier versions, does not properly handle SSL connections, which allows remote attackers to cause a denial of service (crash).        View

Page 19255 of 20943, showing 5 records out of 104715 total, starting on record 96271, ending on 96275

Actions