CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7960  CVE-2003-1136  Candidate  Cross-site scripting (XSS) vulnerability in Chi Kien Uong Guestbook 1.51 allows remote attackers to inject arbitrary web script or HTML via (1) HTML in a posted message or (2) Javascript in an onmouseover attribute in an e-mail address or URL.  Assigned (20050504)  None (candidate not yet proposed)    View
7959  CVE-2003-1135  Candidate  Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send request (sendfile) with a large number of "%" (percent) characters after the Yahoo ID.  Assigned (20050504)  None (candidate not yet proposed)    View
7958  CVE-2003-1134  Candidate  Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the ClassDepth function with a null parameter, which causes a crash instead of generating a null pointer exception.  Assigned (20050504)  None (candidate not yet proposed)    View
7957  CVE-2003-1133  Candidate  Rit Research Labs The Bat! 1.0.11 through 2.0 creates new accounts with insecure ACLs, which allows local users to read other users" email messages.  Assigned (20050504)  None (candidate not yet proposed)    View
7956  CVE-2003-1132  Candidate  The DNS server for Cisco Content Service Switch (CSS) 11000 and 11500, when prompted for a nonexistent AAAA record, responds with response code 3 (NXDOMAIN or "Name Error") instead of response code 0 ("No Error"), which allows remote attackers to cause a denial of service (inaccessible domain) by forcing other DNS servers to send and cache a request for a AAAA record to the vulnerable server.  Assigned (20050421)  None (candidate not yet proposed)    View

Page 19352 of 20943, showing 5 records out of 104715 total, starting on record 96756, ending on 96760

Actions