CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8719  CVE-2004-0291  Candidate  SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote parameter.  Proposed (20040318)  ACCEPT(2) Armstrong, Cole | NOOP(2) Cox, Wall    View
5917  CVE-2002-1533  Candidate  Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contains the malicious script and some encoded linefeed characters (%0a).  Proposed (20030317)  ACCEPT(2) Armstrong, Cole | NOOP(2) Cox, Wall    View
5943  CVE-2002-1559  Candidate  Directory traversal vulnerability in ion-p.exe (aka ion-p) allows remote attackers to read arbitrary files via (1) C: (drive letter) or (2) .. (dot-dot) sequences in the page parameter.  Proposed (20030317)  ACCEPT(2) Armstrong, Cole | NOOP(2) Cox, Wall    View
8789  CVE-2004-0361  Candidate  The Javascript engine in Safari 1.2 and earlier allows remote attackers to cause a denial of service (segmentation fault) by creating a new Array object with a large size value, then writing into that array.  Proposed (20040318)  ACCEPT(2) Armstrong, Cole | NOOP(2) Cox, Wall    View
5516  CVE-2002-1129  Candidate  Buffer overflow in dxterm allows local users to execute arbitrary code via a long -xrm argument.  Modified (20050610)  ACCEPT(2) Armstrong, Cole | NOOP(2) Cox, Wall    View

Page 20183 of 20943, showing 5 records out of 104715 total, starting on record 100911, ending on 100915

Actions