CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8310  CVE-2003-1486  Candidate  Phorum 3.4 through 3.4.2 allows remote attackers to obtain the full path of the web server via an incorrect HTTP request to (1) smileys.php, (2) quick_listrss.php, (3) purge.php, (4) news.php, (5) memberlist.php, (6) forum_listrss.php, (7) forum_list_rdf.php, (8) forum_list.php, or (9) move.php, which leaks the information in an error message.  Assigned (20071024)  None (candidate not yet proposed)    View
8309  CVE-2003-1485  Candidate  Clearswift MAILsweeper 4.0 through 4.3.7 allows remote attackers to bypass filtering via a file attachment that contains "multiple extensions combined with large blocks of white space."  Assigned (20071024)  None (candidate not yet proposed)    View
8308  CVE-2003-1484  Candidate  Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) by creating a DHTML link that uses the AnchorClick "A" object with a blank href attribute.  Assigned (20071024)  None (candidate not yet proposed)    View
8307  CVE-2003-1483  Candidate  FlashFXP 1.4 uses a weak encryption algorithm for user passwords, which allows attackers to decrypt the passwords and gain access.  Assigned (20071024)  None (candidate not yet proposed)    View
8306  CVE-2003-1482  Candidate  The backup configuration file for Microsoft MN-500 wireless base station stores administrative passwords in plaintext, which allows local users to gain access.  Assigned (20071024)  None (candidate not yet proposed)    View

Page 19282 of 20943, showing 5 records out of 104715 total, starting on record 96406, ending on 96410

Actions