CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8280 | CVE-2003-1456 | Candidate | Album.pl 6.1 allows remote attackers to execute arbitrary commands, when an alternative configuration file is used, via unknown attack vectors. | Assigned (20071022) | None (candidate not yet proposed) | View | |
8279 | CVE-2003-1455 | Candidate | Multiple buffer overflows in the launch_bcrelay function in pptpctrl.c in PoPToP 1.1.4-b1 through PoPToP 1.1.4-b3 allow local users to execute arbitrary code. | Assigned (20071022) | None (candidate not yet proposed) | View | |
8278 | CVE-2003-1454 | Candidate | Invision Power Services Invision Board 1.0 through 1.1.1, when a forum is password protected, stores the administrator password in a cookie in plaintext, which could allow remote attackers to gain access. | Assigned (20071022) | None (candidate not yet proposed) | View | |
8277 | CVE-2003-1453 | Candidate | Cross-site scripting (XSS) vulnerability in the MytextSanitizer function in XOOPS 1.3.5 through 1.3.9 and XOOPS 2.0 through 2.0.1 allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in an IMG tag. | Assigned (20071022) | None (candidate not yet proposed) | View | |
8276 | CVE-2003-1452 | Candidate | Untrusted search path vulnerability in Qualcomm qpopper 4.0 through 4.05 allows local users to execute arbitrary code by modifying the PATH environment variable to reference a malicious smbpasswd program. | Assigned (20071022) | None (candidate not yet proposed) | View |
Page 19288 of 20943, showing 5 records out of 104715 total, starting on record 96436, ending on 96440