CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9866 | CVE-2004-1438 | Candidate | The mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access to the repository, to read unauthorized parts of the repository via the svn copy command. | Assigned (20050213) | None (candidate not yet proposed) | View | |
9867 | CVE-2004-1439 | Candidate | Buffer overflow in BlackJumboDog 3.x allows remote attackers to execute arbitrary code via long FTP commands such as (1) USER, (2) PASS, (3) RETR,(4) CWD, (5) XMKD, and (6) XRMD. | Assigned (20050213) | None (candidate not yet proposed) | View | |
9868 | CVE-2004-1440 | Candidate | Multiple heap-based buffer overflows in the modpow function in PuTTY before 0.55 allow (1) remote attackers to execute arbitrary code via an SSH2 packet with a base argument that is larger than the mod argument, which causes the modpow function to write memory before the beginning of its buffer, and (2) remote malicious servers to cause a denial of service (client crash) and possibly execute arbitrary code via a large bignum during authentication. | Assigned (20050213) | None (candidate not yet proposed) | View | |
9869 | CVE-2004-1441 | Candidate | Cross-site scripting (XSS) vulnerability in icq.cgi in Board Power 2.04PF allows remote attackers to inject arbitrary web script or HTML via the action parameter. | Assigned (20050213) | None (candidate not yet proposed) | View | |
9870 | CVE-2004-1442 | Candidate | Cross-site scripting (XSS) vulnerability in db2www CGI interpreter in IBM Net.Data 7 and 7.2 allows remote attackers to inject arbitrary web script or HTML via a macro filename, which is not properly handled by error emssages such as "DTWP001E." | Assigned (20050213) | None (candidate not yet proposed) | View |
Page 19790 of 20943, showing 5 records out of 104715 total, starting on record 98946, ending on 98950