CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10550  CVE-2004-2124  Candidate  The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a PHP remote file inclusion attack via the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412.  Assigned (20050527)  None (candidate not yet proposed)    View
10551  CVE-2004-2125  Candidate  Buffer overflow in blackd.exe for BlackICE PC Protection 3.6 and other versions before 3.6.ccb, with application protection off, allows local users to gain system privileges by modifying the .INI file to contain a long packetLog.fileprefix value.  Assigned (20050527)  None (candidate not yet proposed)    View
10552  CVE-2004-2126  Candidate  The upgrade for BlackICE PC Protection 3.6 and earlier sets insecure permissions for .INI files such as (1) blackice.ini, (2) firewall.ini, (3) protect.ini, or (4) sigs.ini, which allows local users to modify BlackICE configuration or possibly execute arbitrary code by exploiting vulnerabilities in the .INI parsers.  Assigned (20050527)  None (candidate not yet proposed)    View
10553  CVE-2004-2127  Candidate  Directory traversal vulnerability in Web Blog 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file variable.  Assigned (20050527)  None (candidate not yet proposed)    View
10554  CVE-2004-2128  Candidate  Cross-site scripting (XSS) vulnerability in BRS WebWeaver 1.07 allows remote attackers to execute arbitrary script as other users via the query string to ISAPISkeleton.dll.  Assigned (20050527)  None (candidate not yet proposed)    View

Page 19331 of 20943, showing 5 records out of 104715 total, starting on record 96651, ending on 96655

Actions