CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10235  CVE-2004-1808  Candidate  Extcompose in metamail does not verify the output file before writing to it, which allows local users to overwrite arbitrary files via a symlink attack.  Assigned (20050504)  None (candidate not yet proposed)    View
10491  CVE-2004-2065  Candidate  DansGuardian 2.8 and earlier allows remote attackers to bypass the extension filtering rule via a hex encoded extension or . in the filename.  Assigned (20050504)  None (candidate not yet proposed)    View
10236  CVE-2004-1809  Candidate  Cross-site scripting (XSS) vulnerability in phpBB 2.0.6d and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) postdays parameter to viewtopic.php or (2) topicdays parameter to viewforum.php.  Assigned (20050504)  None (candidate not yet proposed)    View
10492  CVE-2004-2066  Candidate  SQL injection vulnerability in session.php in LinPHA 0.9.4 allows remote attackers to execute arbitrary SQL code and bypass authentication via the (1) linpha_userid or (2) linpha_password cookies.  Assigned (20050504)  None (candidate not yet proposed)    View
10237  CVE-2004-1810  Candidate  The Javascript engine in Opera 7.23 allows remote attackers to cause a denial of service (crash) by creating a new Array object with a large size value, then writing into that array.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 19473 of 20943, showing 5 records out of 104715 total, starting on record 97361, ending on 97365

Actions