CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9089  CVE-2004-0661  Candidate  Integer signedness error in D-Link AirPlus DI-614+ running firmware 2.30 and earlier allows remote attackers to cause a denial of service (IP lease depletion) via a DHCP request with the LEASETIME option set to -1, which makes the DHCP lease valid for thirteen or more years.  Assigned (20040712)  None (candidate not yet proposed)    View
9090  CVE-2004-0662  Candidate  PowerPortal 1.x allows remote attackers to gain sensitive information via invalid or missing parameters in HTTP requests to (1) resize.php or (2) modules.php, which reveals the path in an error message.  Assigned (20040712)  None (candidate not yet proposed)    View
9091  CVE-2004-0663  Candidate  Cross-site scripting (XSS) vulnerability in modules.php in PowerPortal 1.x allows remote attackers to inject arbitrary script or HTML via the (1) id parameter to the (a) private_messages module; (2) search parameter to the (b) links and (c) content modules; and (3) files parameter to the gallery module.  Assigned (20040712)  None (candidate not yet proposed)    View
9092  CVE-2004-0664  Candidate  Directory traversal vulnerability in modules.php in PowerPortal 1.x allows remote attackers to list arbitrary directories via a .. (dot dot) in the files parameter.  Assigned (20040712)  None (candidate not yet proposed)    View
9093  CVE-2004-0665  Candidate  csFAQ.cgi in csFAQ allows remote attackers to gain sensitive information via an invalid database parameter, which reveals the path to the web server in an error message.  Assigned (20040712)  None (candidate not yet proposed)    View

Page 20034 of 20943, showing 5 records out of 104715 total, starting on record 100166, ending on 100170

Actions