CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10089  CVE-2004-1661  Candidate  MailWorks Professional allows remote attackers to bypass authentication and gain privileges via a cookie that contains "auth=1" and "uId=1."  Assigned (20050221)  None (candidate not yet proposed)    View
10090  CVE-2004-1662  Candidate  YaBB SE 1.5.1 allows remote attackers to obtain sensitive information via a direct HTTP request to Admin.php, which reveals the full path in a PHP error message.  Assigned (20050221)  None (candidate not yet proposed)    View
10091  CVE-2004-1663  Candidate  Engenio/LSI Logic storage controllers, as used in products such as Storagetek D280, and IBM DS4100 (formerly FastT 100) and Brocade SilkWorm Switches, allow remote attackers to cause a denial of service (freeze and possible data corruption) via crafted TCP packets.  Assigned (20050221)  None (candidate not yet proposed)    View
10092  CVE-2004-1664  Candidate  Call of Duty 1.4 and earlier allows remote attackers to cause a denial of service (game end) via a large (1) query or (2) reply packet, which is not properly handled by the buffer overflow protection mechanism. NOTE: this issue might overlap CVE-2005-0430.  Assigned (20050221)  None (candidate not yet proposed)    View
10093  CVE-2004-1665  Candidate  Cross-site scripting (XSS) vulnerability in index.php in PsNews 1.1 allows remote attackers to inject arbitrary web script or HTML via the no parameter.  Assigned (20050221)  None (candidate not yet proposed)    View

Page 19723 of 20943, showing 5 records out of 104715 total, starting on record 98611, ending on 98615

Actions