CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10757  CVE-2004-2331  Candidate  ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection methods to access trusted Java objects without using the CreateObject function or cfobject tag.  Assigned (20050816)  None (candidate not yet proposed)    View
10758  CVE-2004-2332  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in CPAN WWW::Form before 1.13 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.  Assigned (20050816)  None (candidate not yet proposed)    View
10759  CVE-2004-2333  Candidate  Bodington 2.1.0 RC1 and earlier does not secure the file upload area, which allows remote attackers to read uploaded files.  Assigned (20050816)  None (candidate not yet proposed)    View
10760  CVE-2004-2334  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in EMU Webmail 5.2.7 allow remote attackers to inject arbitrary web script or HTML via (1) a hex-encoded value to the variable parameter in emumail.fcgi, (2) the folder parameter in emumail.fcgi, or Javascript in the (3) username or (4) password field in the login page.  Assigned (20050816)  None (candidate not yet proposed)    View
10761  CVE-2004-2335  Candidate  The Macromedia installers and e-licensing client on Mac OS X, as used for Macromedia Contribute 2, Director, Dreamweaver, Fireworks, Flash, and Studio, install the AuthenticationService setuid and writable by other users, which allows local users to gain privileges by modifying the program.  Assigned (20050816)  None (candidate not yet proposed)    View

Page 1929 of 20943, showing 5 records out of 104715 total, starting on record 9641, ending on 9645

Actions