CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9129 | CVE-2004-0701 | Candidate | Sun Ray Server Software (SRSS) 1.3 and 2.0 for Solaris 2.6, 7 and 8 does not properly detect a smartcard removal when the card is quickly removed, reinserted, and removed again, which could cause a user session to stay logged in and allow local users to gain unauthorized access. | Assigned (20040720) | None (candidate not yet proposed) | View | |
9130 | CVE-2004-0702 | Candidate | DBI in Bugzilla 2.17.1 through 2.17.7 displays the database password in an error message when the SQL server is not running, which could allow remote attackers to gain sensitive information. | Assigned (20040720) | None (candidate not yet proposed) | View | |
9131 | CVE-2004-0703 | Candidate | Unknown vulnerability in the administrative controls in Bugzilla 2.17.1 through 2.17.7 allows users with "grant membership" privileges to grant memberships to groups that the user does not control. | Assigned (20040720) | None (candidate not yet proposed) | View | |
9132 | CVE-2004-0704 | Candidate | Unknown vulnerability in (1) duplicates.cgi and (2) buglist.cgi in Bugzilla 2.16.x before 2.16.6, 2.18 before 2.18rc1, when configured to hide products, allows remote attackers to view hidden products. | Assigned (20040720) | None (candidate not yet proposed) | View | |
9133 | CVE-2004-0705 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in (1) editcomponents.cgi, (2) editgroups.cgi, (3) editmilestones.cgi, (4) editproducts.cgi, (5) editusers.cgi, and (6) editversions.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allow remote attackers to execute arbitrary JavaScript as other users via a URL parameter. | Assigned (20040720) | None (candidate not yet proposed) | View |
Page 20027 of 20943, showing 5 records out of 104715 total, starting on record 100131, ending on 100135