CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10151 | CVE-2004-1723 | Candidate | The (1) updateuser.php and (2) forums_prune.php scripts in PHP-Fusion 4.00 allow remote attackers to obtain sensitive information via a direct HTTP request, which reveals the installation path in an error message. | Assigned (20050226) | None (candidate not yet proposed) | View | |
10152 | CVE-2004-1724 | Candidate | The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/write/execute (777), which allows remote attackers to download or view database backups, which have easily guessable filenames and contain the administrator username and password. | Assigned (20050226) | None (candidate not yet proposed) | View | |
10153 | CVE-2004-1725 | Candidate | Stack-based buffer overflow in xvbmp.c in XV allows remote attackers to execute arbitrary code via a crafted image file. | Assigned (20050226) | None (candidate not yet proposed) | View | |
10154 | CVE-2004-1726 | Candidate | Multiple integer overflows in (1) xviris.c, (2) xvpcx.c, and (3) xvpm.c in XV allow remote attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow. | Assigned (20050226) | None (candidate not yet proposed) | View | |
10155 | CVE-2004-1727 | Candidate | BadBlue 2.5 allows remote attackers to cause a denial of service (refuse HTTP connections) via a large number of connections from the same IP address. | Assigned (20050226) | None (candidate not yet proposed) | View |
Page 19700 of 20943, showing 5 records out of 104715 total, starting on record 98496, ending on 98500