CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10114  CVE-2004-1686  Candidate  Internet Explorer 6.0 in Windows XP SP2 allows remote attackers to bypass the Information Bar prompt for ActiveX and Javascript via an XHTML page that contains an Internet Explorer formatted comment between the DOCTYPE tag and the HTML tag, as demonstrated using the DesignScience MathPlayer ActiveX plugin.  Assigned (20050221)  None (candidate not yet proposed)    View
10115  CVE-2004-1687  Candidate  CRLF injection vulnerability in down.asp for Snitz Forums 2000 3.4.04 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the location parameter.  Assigned (20050221)  None (candidate not yet proposed)    View
10116  CVE-2004-1688  Candidate  Pigeon Server 3.02.0143 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a long login name sent to port 3103.  Assigned (20050221)  None (candidate not yet proposed)    View
10117  CVE-2004-1689  Candidate  sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the temporary file before quitting sudoedit.  Assigned (20050221)  None (candidate not yet proposed)    View
10118  CVE-2004-1690  Candidate  Cross-site scripting (XSS) vulnerability in the Web Server in DNS4Me 3.0.0.4 allows remote attackers to execute arbitrary web script or HTML via the URL.  Assigned (20050221)  None (candidate not yet proposed)    View

Page 19728 of 20943, showing 5 records out of 104715 total, starting on record 98636, ending on 98640

Actions