CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10151  CVE-2004-1723  Candidate  The (1) updateuser.php and (2) forums_prune.php scripts in PHP-Fusion 4.00 allow remote attackers to obtain sensitive information via a direct HTTP request, which reveals the installation path in an error message.  Assigned (20050226)  None (candidate not yet proposed)    View
10152  CVE-2004-1724  Candidate  The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/write/execute (777), which allows remote attackers to download or view database backups, which have easily guessable filenames and contain the administrator username and password.  Assigned (20050226)  None (candidate not yet proposed)    View
10153  CVE-2004-1725  Candidate  Stack-based buffer overflow in xvbmp.c in XV allows remote attackers to execute arbitrary code via a crafted image file.  Assigned (20050226)  None (candidate not yet proposed)    View
10154  CVE-2004-1726  Candidate  Multiple integer overflows in (1) xviris.c, (2) xvpcx.c, and (3) xvpm.c in XV allow remote attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow.  Assigned (20050226)  None (candidate not yet proposed)    View
10155  CVE-2004-1727  Candidate  BadBlue 2.5 allows remote attackers to cause a denial of service (refuse HTTP connections) via a large number of connections from the same IP address.  Assigned (20050226)  None (candidate not yet proposed)    View

Page 19700 of 20943, showing 5 records out of 104715 total, starting on record 98496, ending on 98500

Actions