CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9104  CVE-2004-0676  Candidate  Directory traversal vulnerability in Fastream NETFile FTP/Web Server 6.7.2.1085 and earlier allows remote attackers to create or delete arbitrary files via .. (dot dot) and // (double slash) sequences in the filename parameter.  Assigned (20040712)  None (candidate not yet proposed)    View
9105  CVE-2004-0677  Candidate  Fastream NETFile FTP Server 6.7.2.1085 and earlier allows remote attackers to cause a denial of service (temporary hang) via the cd command with an unusual argument, possibly due to multiple leading slashes and/or an access to the floppy drive ("A").  Assigned (20040712)  None (candidate not yet proposed)    View
9106  CVE-2004-0678  Candidate  Cross-site scripting (XSS) in one2planet.infolet.InfoServlet in 12Planet Chat Server 2.9 allows remote attackers to execute arbitrary script as other users via the page parameter.  Assigned (20040712)  None (candidate not yet proposed)    View
9107  CVE-2004-0679  Candidate  The IP cloaking feature (cloak.c) in UnrealIRCd 3.2, and possibly other versions, uses a weak hashing scheme to hide IP addresses, which could allow remote attackers to use brute force methods to gain other user"s IP addresses.  Assigned (20040712)  None (candidate not yet proposed)    View
9108  CVE-2004-0680  Candidate  Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password has been changed for the HTTP interface, which could allow remote attackers to gain unauthorized access.  Assigned (20040712)  None (candidate not yet proposed)    View

Page 20037 of 20943, showing 5 records out of 104715 total, starting on record 100181, ending on 100185

Actions