CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10235 | CVE-2004-1808 | Candidate | Extcompose in metamail does not verify the output file before writing to it, which allows local users to overwrite arbitrary files via a symlink attack. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10491 | CVE-2004-2065 | Candidate | DansGuardian 2.8 and earlier allows remote attackers to bypass the extension filtering rule via a hex encoded extension or . in the filename. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10236 | CVE-2004-1809 | Candidate | Cross-site scripting (XSS) vulnerability in phpBB 2.0.6d and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) postdays parameter to viewtopic.php or (2) topicdays parameter to viewforum.php. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10492 | CVE-2004-2066 | Candidate | SQL injection vulnerability in session.php in LinPHA 0.9.4 allows remote attackers to execute arbitrary SQL code and bypass authentication via the (1) linpha_userid or (2) linpha_password cookies. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10237 | CVE-2004-1810 | Candidate | The Javascript engine in Opera 7.23 allows remote attackers to cause a denial of service (crash) by creating a new Array object with a large size value, then writing into that array. | Assigned (20050504) | None (candidate not yet proposed) | View |
Page 19473 of 20943, showing 5 records out of 104715 total, starting on record 97361, ending on 97365