CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9640 | CVE-2004-1212 | Candidate | Directory traversal vulnerability in btdownload.php in Blog Torrent preview 0.8 allows remote attackers to download arbitrary files via a .. (dot dot) in the file argument. | Assigned (20041214) | None (candidate not yet proposed) | View | |
9641 | CVE-2004-1213 | Candidate | Cross-site scripting (XSS) vulnerability in index.php in Advanced Guestbook 2.3.1, 2.2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the entry parameter. | Assigned (20041214) | None (candidate not yet proposed) | View | |
9642 | CVE-2004-1214 | Candidate | Format string vulnerability in Kreed 1.05 and earlier allows remote attackers to execute arbitrary code via format specifiers in (1) a nickname or (2) message text. | Assigned (20041214) | None (candidate not yet proposed) | View | |
9643 | CVE-2004-1215 | Candidate | Kreed 1.05 and earlier allows remote attackers to cause a denial of service (server disconnect) via a long UDP packet, which causes a "message too long" socket error. | Assigned (20041214) | None (candidate not yet proposed) | View | |
9644 | CVE-2004-1216 | Candidate | The scripts that handle players in Kreed 1.05 and earlier allow remote attackers to cause a denial of service (server freeze) via a long (1) nickname or (2) model type, which generates dialog boxes on the server that must be manually handled before the server continues the game. | Assigned (20041214) | None (candidate not yet proposed) | View |
Page 19926 of 20943, showing 5 records out of 104715 total, starting on record 99626, ending on 99630