CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9089 | CVE-2004-0661 | Candidate | Integer signedness error in D-Link AirPlus DI-614+ running firmware 2.30 and earlier allows remote attackers to cause a denial of service (IP lease depletion) via a DHCP request with the LEASETIME option set to -1, which makes the DHCP lease valid for thirteen or more years. | Assigned (20040712) | None (candidate not yet proposed) | View | |
9090 | CVE-2004-0662 | Candidate | PowerPortal 1.x allows remote attackers to gain sensitive information via invalid or missing parameters in HTTP requests to (1) resize.php or (2) modules.php, which reveals the path in an error message. | Assigned (20040712) | None (candidate not yet proposed) | View | |
9091 | CVE-2004-0663 | Candidate | Cross-site scripting (XSS) vulnerability in modules.php in PowerPortal 1.x allows remote attackers to inject arbitrary script or HTML via the (1) id parameter to the (a) private_messages module; (2) search parameter to the (b) links and (c) content modules; and (3) files parameter to the gallery module. | Assigned (20040712) | None (candidate not yet proposed) | View | |
9092 | CVE-2004-0664 | Candidate | Directory traversal vulnerability in modules.php in PowerPortal 1.x allows remote attackers to list arbitrary directories via a .. (dot dot) in the files parameter. | Assigned (20040712) | None (candidate not yet proposed) | View | |
9093 | CVE-2004-0665 | Candidate | csFAQ.cgi in csFAQ allows remote attackers to gain sensitive information via an invalid database parameter, which reveals the path to the web server in an error message. | Assigned (20040712) | None (candidate not yet proposed) | View |
Page 20034 of 20943, showing 5 records out of 104715 total, starting on record 100166, ending on 100170