CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8280  CVE-2003-1456  Candidate  Album.pl 6.1 allows remote attackers to execute arbitrary commands, when an alternative configuration file is used, via unknown attack vectors.  Assigned (20071022)  None (candidate not yet proposed)    View
8279  CVE-2003-1455  Candidate  Multiple buffer overflows in the launch_bcrelay function in pptpctrl.c in PoPToP 1.1.4-b1 through PoPToP 1.1.4-b3 allow local users to execute arbitrary code.  Assigned (20071022)  None (candidate not yet proposed)    View
8278  CVE-2003-1454  Candidate  Invision Power Services Invision Board 1.0 through 1.1.1, when a forum is password protected, stores the administrator password in a cookie in plaintext, which could allow remote attackers to gain access.  Assigned (20071022)  None (candidate not yet proposed)    View
8277  CVE-2003-1453  Candidate  Cross-site scripting (XSS) vulnerability in the MytextSanitizer function in XOOPS 1.3.5 through 1.3.9 and XOOPS 2.0 through 2.0.1 allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in an IMG tag.  Assigned (20071022)  None (candidate not yet proposed)    View
8276  CVE-2003-1452  Candidate  Untrusted search path vulnerability in Qualcomm qpopper 4.0 through 4.05 allows local users to execute arbitrary code by modifying the PATH environment variable to reference a malicious smbpasswd program.  Assigned (20071022)  None (candidate not yet proposed)    View

Page 19288 of 20943, showing 5 records out of 104715 total, starting on record 96436, ending on 96440

Actions