CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6090 | CVE-2002-1708 | Candidate | Cross-site scripting vulnerability (XSS) in BasiliX Webmail 1.10 allows remote attackers to execute arbitrary script as other users by injecting script into the (1) subject or (2) message fields. | Assigned (20050621) | None (candidate not yet proposed) | View | |
4299 | CVE-2001-1499 | Candidate | Check Point VPN-1 4.1SP4 using SecuRemote returns different error messages for valid and invalid users, with prompts that vary depending on the authentication method being used, which makes it easier for remote attackers to conduct brute force attacks. | Assigned (20050621) | None (candidate not yet proposed) | View | |
6091 | CVE-2002-1709 | Candidate | SQL injection vulnerability in BasiliX Webmail 1.10 allows remote attackers to obtain sensitive information or possibly modify data via the id variable. | Assigned (20050621) | None (candidate not yet proposed) | View | |
4300 | CVE-2001-1500 | Candidate | ProFTPD 1.2.2rc2, and possibly other versions, does not properly verify reverse-resolved hostnames by performing forward resolution, which allows remote attackers to bypass ACLs or cause an incorrect client hostname to be logged. | Assigned (20050621) | None (candidate not yet proposed) | View | |
6092 | CVE-2002-1710 | Candidate | The attachment capability in Compose Mail in BasiliX Webmail 1.1.0 does not check whether the attachment was uploaded by the user or came from a HTTP POST, which could allow local users to steal sensitive information like a password file. | Assigned (20050621) | None (candidate not yet proposed) | View |
Page 19259 of 20943, showing 5 records out of 104715 total, starting on record 96291, ending on 96295