CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9866  CVE-2004-1438  Candidate  The mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access to the repository, to read unauthorized parts of the repository via the svn copy command.  Assigned (20050213)  None (candidate not yet proposed)    View
9867  CVE-2004-1439  Candidate  Buffer overflow in BlackJumboDog 3.x allows remote attackers to execute arbitrary code via long FTP commands such as (1) USER, (2) PASS, (3) RETR,(4) CWD, (5) XMKD, and (6) XRMD.  Assigned (20050213)  None (candidate not yet proposed)    View
9868  CVE-2004-1440  Candidate  Multiple heap-based buffer overflows in the modpow function in PuTTY before 0.55 allow (1) remote attackers to execute arbitrary code via an SSH2 packet with a base argument that is larger than the mod argument, which causes the modpow function to write memory before the beginning of its buffer, and (2) remote malicious servers to cause a denial of service (client crash) and possibly execute arbitrary code via a large bignum during authentication.  Assigned (20050213)  None (candidate not yet proposed)    View
9869  CVE-2004-1441  Candidate  Cross-site scripting (XSS) vulnerability in icq.cgi in Board Power 2.04PF allows remote attackers to inject arbitrary web script or HTML via the action parameter.  Assigned (20050213)  None (candidate not yet proposed)    View
9870  CVE-2004-1442  Candidate  Cross-site scripting (XSS) vulnerability in db2www CGI interpreter in IBM Net.Data 7 and 7.2 allows remote attackers to inject arbitrary web script or HTML via a macro filename, which is not properly handled by error emssages such as "DTWP001E."  Assigned (20050213)  None (candidate not yet proposed)    View

Page 19790 of 20943, showing 5 records out of 104715 total, starting on record 98946, ending on 98950

Actions