CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10061 | CVE-2004-1633 | Candidate | process_bug.cgi in Bugzilla 2.9 through 2.18rc2 and 2.19 from CVS does not check edit permissions on the keywords field, which allows remote authenticated users to modify the keywords in a bug via the keywordaction parameter. | Assigned (20050220) | None (candidate not yet proposed) | View | |
10062 | CVE-2004-1634 | Candidate | show_bug.cgi in Bugzilla 2.17.1 through 2.18rc2 and 2.19 from CVS, when using the insidergroup feature and exporting a bug to XML, shows comments and attachment summaries which are marked as private, which allows remote attackers to gain sensitive information. | Assigned (20050220) | None (candidate not yet proposed) | View | |
10063 | CVE-2004-1635 | Candidate | Bugzilla 2.17.1 through 2.18rc2 and 2.19 from cvs, when using the insidergroup feature, does not sufficiently protect private attachments when there are changes to the metadata, such as filename, description, MIME type, or review flags, which allows remote authenticated users to obtain sensitive information when (1) viewing the bug activity log or (2) receiving bug change notification mails. | Assigned (20050220) | None (candidate not yet proposed) | View | |
10064 | CVE-2004-1636 | Candidate | Heap-based buffer overflow in the WvTFTPServer::new_connection function in wvtftpserver.cc for WvTftp 0.9 allows remote attackers to execute arbitrary code via a long option string in a TFTP packet. | Assigned (20050220) | None (candidate not yet proposed) | View | |
10065 | CVE-2004-1637 | Candidate | The Hawking Technologies HAR11A modem/router allows remote attackers to obtain sensitive information by connecting to port 254, which displays a management interface and information on established connections. | Assigned (20050220) | None (candidate not yet proposed) | View |
Page 19750 of 20943, showing 5 records out of 104715 total, starting on record 98746, ending on 98750