CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4494  CVE-2002-0100  Candidate  AOL AOLserver 3.4.2 Win32 allows remote attackers to bypass authentication and read password-protected files via a URL that directly references the file.  Modified (20050710)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese    View
8673  CVE-2004-0245  Candidate  Web Crossing 4.x and 5.x allows remote attackers to cause a denial of service (crash) by sending a HTTP POST request with a large or negative Content-Length, which causes an integer divide-by-zero.  Modified (20050710)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View
8750  CVE-2004-0322  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to execute arbitrary script as other users via the (1) member parameter in member.php, (2) uid parameter in u2uadmin.php, (3) user parameter in editprofile.php, (4) an onmouseover event in an align tag when bbcode is allowed, or (5) img tag where bbcode is allowed.  Modified (20050718)  ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall    View
8770  CVE-2004-0342  Candidate  WFTPD Pro Server 3.21 Release 1, with the XeroxDocutech option enabled, allows local users to cause a denial of service (crash) via a (1) MKD or (2) XMKD command that causes an absolute path of 260 characters to be used, which overwrites a cookie with a null character, possibly due to an off-by-one error.  Modified (20050718)  ACCEPT(2) Armstrong, Wall | NOOP(2) Cole, Cox    View
8768  CVE-2004-0340  Candidate  Stack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Server 3.10 allows local users to execute arbitrary code via long (1) LIST, (2) NLST, or (3) STAT commands.  Modified (20050719)  ACCEPT(2) Armstrong, Wall | NOOP(2) Cole, Cox    View

Page 20447 of 20943, showing 5 records out of 104715 total, starting on record 102231, ending on 102235

Actions