CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8305  CVE-2003-1481  Candidate  CommuniGate Pro 3.1 through 4.0.6 sends the session ID in the referer field for an HTTP request for an image, which allows remote attackers to hijack mail sessions via an e-mail with an IMG tag that references a malicious URL that captures the referer.  Assigned (20071024)  None (candidate not yet proposed)    View
8304  CVE-2003-1480  Candidate  MySQL 3.20 through 4.1.0 uses a weak algorithm for hashed passwords, which makes it easier for attackers to decrypt the password via brute force methods.  Assigned (20071024)  None (candidate not yet proposed)    View
8303  CVE-2003-1479  Candidate  Cross-site scripting (XSS) vulnerability in webcamXP 1.02.432 and 1.02.535 allows remote attackers to inject arbitrary web script or HTML via the message field.  Assigned (20071024)  None (candidate not yet proposed)    View
8302  CVE-2003-1478  Candidate  Konqueror in KDE 3.0.3 allows remote attackers to cause a denial of service (core dump) via a web page that begins with a "xFFxFE" byte sequence and a large number of CRLF sequences, as demonstrated using freeze.htm.  Assigned (20071024)  None (candidate not yet proposed)    View
8301  CVE-2003-1477  Candidate  MAILsweeper for SMTP 4.3.6 and 4.3.7 allows remote attackers to cause a denial of service (CPU consumption) via a PowerPoint attachment that either (1) is corrupt or (2) contains "embedded objects."  Assigned (20071024)  None (candidate not yet proposed)    View

Page 19283 of 20943, showing 5 records out of 104715 total, starting on record 96411, ending on 96415

Actions