CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8495  CVE-2004-0067  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7) imageview.php, (8) calendar.php, (9) gedrecord.php, (10) login.php, and (11) gdbi_interface.php. NOTE: some aspects of vector 10 were later reported to affect 4.1.  Modified (20090127)  ACCEPT(3) Armstrong, Baker, Williams | NOOP(3) Cole, Cox, Wall  Williams> http://sourceforge.net/project/showfiles.php?group_id=55456  View
8664  CVE-2004-0236  Candidate  SQL injection vulnerability in login.asp in thePHOTOtool allows remote attackers to gain unauthorized access via the password field.  Modified (20090127)  NOOP(4) Armstrong, Cole, Cox, Wall    View
15  CVE-1999-0015  Candidate  Teardrop IP denial of service.  Modified (20090302)  ACCEPT(1) Wall | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> XF: teardrop-mod | Christey> Not sure how many separate "instances" of Teardrop there are. | See: CVE-1999-0015, CVE-1999-0104, CVE-1999-0257, CVE-1999-0258 | Christey> See the SCO advisory at: | http://www.securityfocus.com/templates/advisory.html?id=1411 | which may further clarify the issue. | Christey> MSKB:Q154174 | MSKB:Q154174 (CVE-1999-0015) and MSKB:Q179129 (CVE-1999-0104) | indicate that CVE-1999-0015 was fixed in NT SP3, but | CVE-1999-0104 was not. Thus CD:SF-LOC suggests that the | problems keep separate candidates because one problem appears | in a different version than the other. | Christey> BID:124 | http://www.securityfocus.com/bid/124 | Consider MSKB:Q154174 | http://support.microsoft.com/support/kb/articles/q154/1/74.asp | Consider BUGTRAQ:19971113 Linux IP fragment overlap bug | http://www.securityfocus.com/archive/1/8014  View
3615  CVE-2001-0809  Candidate  Vulnerability in CIFS/9000 Server (SAMBA) A.01.06 and earlier in HP-UX 11.0 and 11.11, when configured as a print server, allows local users to overwrite arbitrary files by modifying certain resources.  Modified (20090302)  ACCEPT(4) Armstrong, Bishop, Cole, Foat | NOOP(1) Wall | REJECT(1) Frech  Frech> See XF:samba-tmpfile-symlink(6396). | Discovery and advisory are two months apart, and no other Samba | issues seem to exist around that timespan.  View
8482  CVE-2004-0054  Candidate  Multiple vulnerabilities in the H.323 protocol implementation for Cisco IOS 11.3T through 12.2T allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.  Modified (20090302)  ACCEPT(5) Armstrong, Baker, Cole, Green, Wall | NOOP(1) Cox    View

Page 20503 of 20943, showing 5 records out of 104715 total, starting on record 102511, ending on 102515

Actions