CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9134  CVE-2004-0706  Candidate  Bugzilla 2.17.5 through 2.17.7 embeds the password in an image URL, which could allow local users to view the password in the web server log files.  Assigned (20040720)  None (candidate not yet proposed)    View
9135  CVE-2004-0707  Candidate  SQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allows remote attackers with privileges to grant membership to any group to execute arbitrary SQL.  Assigned (20040720)  None (candidate not yet proposed)    View
9136  CVE-2004-0708  Candidate  MoinMoin 1.2.1 and earlier allows remote attackers to gain privileges by creating a user with the same name as an existing group that has higher privileges.  Assigned (20040720)  None (candidate not yet proposed)    View
9137  CVE-2004-0709  Candidate  HP OpenView Select Access 5.0 through 6.0 does not correctly decode UTF-8 encoded unicode characters in a URL, which could allow remote attackers to bypass access restrictions.  Assigned (20040720)  None (candidate not yet proposed)    View
9138  CVE-2004-0710  Candidate  IP Security VPN Services Module (VPNSM) in Cisco Catalyst 6500 Series Switch and the Cisco 7600 Series Internet Routers running IOS before 12.2(17b)SXA, before 12.2(17d)SXB, or before 12.2(14)SY03 could allow remote attackers to cause a denial of service (device crash and reload) via a malformed Internet Key Exchange (IKE) packet.  Assigned (20040720)  None (candidate not yet proposed)    View

Page 20028 of 20943, showing 5 records out of 104715 total, starting on record 100136, ending on 100140

Actions