CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10372  CVE-2004-1946  Candidate  Format string vulnerability in the PRINT_ERROR function in common.c for Cherokee Web Server 0.4.16 and earlier allows local users to execute arbitrary code via format string specifiers in the -C command line argument. NOTE: it is not clear whether this issue could be exploited remotely, or if Cherokee is running at escalated privileges. Therefore it might not be a vulnerability.  Assigned (20050504)  None (candidate not yet proposed)    View
10373  CVE-2004-1947  Candidate  The AVXSCANONLINE.AvxScanOnlineCtrl.1 ActiveX control in BitDefender Scan Online allows remote attackers to (1) obtain sensitive information such as system drives and contents or (2) use the RequestFile method to download and execute arbitrary code via an object codebase that uses bitdefender.cab.  Assigned (20050504)  None (candidate not yet proposed)    View
10374  CVE-2004-1948  Candidate  NcFTP client 3.1.6 and 3.1.7, when the username and password are included in an FTP URL that is provided on the command line, allows local users to obtain sensitive information via "ps aux," which displays the URL in the process list.  Assigned (20050504)  None (candidate not yet proposed)    View
10375  CVE-2004-1949  Candidate  SQL injection vulnerability in PostNuke 7.2.6 and earlier allows remote attackers to execute arbitrary SQL via (1) the sif parameter to index.php in the Comments module or (2) timezoneoffset parameter to changeinfo.php in the Your_Account module.  Assigned (20050504)  None (candidate not yet proposed)    View
10376  CVE-2004-1950  Candidate  phpBB 2.0.8a and earlier trusts the IP address that is in the X-Forwarded-For in the HTTP header, which allows remote attackers to spoof IP addresses.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 19443 of 20943, showing 5 records out of 104715 total, starting on record 97211, ending on 97215

Actions