CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10525  CVE-2004-2099  Candidate  Buffer overflow in Need for Speed Hot Pursuit 2.0 client (NFSHP2), version 242 and earlier, allows remote attackers (servers) to execute arbitrary code via long (1) gamename, (2) gamever, (3) hostname, (4) gametype, (5) mapname or (6) gamemode commands.  Assigned (20050527)  None (candidate not yet proposed)    View
10526  CVE-2004-2100  Candidate  GeoHttpServer, when configured to authenticate users, allows remote attackers to bypass authentication and access unauthorized files via a URL that contains %0a%0a (encoded newlines).  Assigned (20050527)  None (candidate not yet proposed)    View
10527  CVE-2004-2101  Candidate  The sysinfo script in GeoHttpServer allows remote attackers to cause a denial of service (crash) via a long pwd parameter, possibly triggering a buffer overflow.  Assigned (20050527)  None (candidate not yet proposed)    View
10528  CVE-2004-2102  Candidate  Cross-site scripting (XSS) vulnerability in FREESCO 2.05, a modified version of thttpd, allows remote attackers to inject arbitrary web script or HTML via the test parameter.  Assigned (20050527)  None (candidate not yet proposed)    View
10529  CVE-2004-2103  Candidate  Cross-site scripting (XSS) vulnerability in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to process arbitrary script or HTML as other users via (1) a malformed request for a Perl program with script in the filename, (2) the User.id parameter to the webacc servlet, (3) the GWAP.version parameter to webacc, or (4) a URL request for a .bas file with script in the filename.  Assigned (20050527)  None (candidate not yet proposed)    View

Page 19326 of 20943, showing 5 records out of 104715 total, starting on record 96626, ending on 96630

Actions