CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7855  CVE-2003-1031  Candidate  Cross-site scripting (XSS) vulnerability in register.php for vBulletin 3.0 Beta 2 allows remote attackers to inject arbitrary HTML or web script via optional fields such as (1) "Interests-Hobbies", (2) "Biography", or (3) "Occupation."  Assigned (20040121)  None (candidate not yet proposed)    View
7854  CVE-2003-1030  Candidate  Buffer overflow in DameWare Mini Remote Control before 3.73 allows remote attackers to execute arbitrary code via a long pre-authentication request to TCP port 6129.  Assigned (20040115)  None (candidate not yet proposed)    View
7853  CVE-2003-1029  Candidate  The L2TP protocol parser in tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (infinite loop and memory consumption) via a packet with invalid data to UDP port 1701, which causes l2tp_avp_print to use a bad length value when calling print_octets.  Assigned (20040114)  None (candidate not yet proposed)    View
7852  CVE-2003-1028  Candidate  The download function of Internet Explorer 6 SP1 allows remote attackers to obtain the cache directory name via an HTTP response with an invalid ContentType and a .htm file, which could allow remote attackers to bypass security mechanisms that rely on random names, as demonstrated by threadid10008.  Assigned (20040107)  None (candidate not yet proposed)    View
7851  CVE-2003-1027  Candidate  Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."  Assigned (20040107)  None (candidate not yet proposed)    View

Page 19373 of 20943, showing 5 records out of 104715 total, starting on record 96861, ending on 96865

Actions