CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8495 | CVE-2004-0067 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7) imageview.php, (8) calendar.php, (9) gedrecord.php, (10) login.php, and (11) gdbi_interface.php. NOTE: some aspects of vector 10 were later reported to affect 4.1. | Modified (20090127) | ACCEPT(3) Armstrong, Baker, Williams | NOOP(3) Cole, Cox, Wall | Williams> http://sourceforge.net/project/showfiles.php?group_id=55456 | View |
8664 | CVE-2004-0236 | Candidate | SQL injection vulnerability in login.asp in thePHOTOtool allows remote attackers to gain unauthorized access via the password field. | Modified (20090127) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
15 | CVE-1999-0015 | Candidate | Teardrop IP denial of service. | Modified (20090302) | ACCEPT(1) Wall | MODIFY(1) Frech | REVIEWING(1) Christey | Frech> XF: teardrop-mod | Christey> Not sure how many separate "instances" of Teardrop there are. | See: CVE-1999-0015, CVE-1999-0104, CVE-1999-0257, CVE-1999-0258 | Christey> See the SCO advisory at: | http://www.securityfocus.com/templates/advisory.html?id=1411 | which may further clarify the issue. | Christey> MSKB:Q154174 | MSKB:Q154174 (CVE-1999-0015) and MSKB:Q179129 (CVE-1999-0104) | indicate that CVE-1999-0015 was fixed in NT SP3, but | CVE-1999-0104 was not. Thus CD:SF-LOC suggests that the | problems keep separate candidates because one problem appears | in a different version than the other. | Christey> BID:124 | http://www.securityfocus.com/bid/124 | Consider MSKB:Q154174 | http://support.microsoft.com/support/kb/articles/q154/1/74.asp | Consider BUGTRAQ:19971113 Linux IP fragment overlap bug | http://www.securityfocus.com/archive/1/8014 | View |
3615 | CVE-2001-0809 | Candidate | Vulnerability in CIFS/9000 Server (SAMBA) A.01.06 and earlier in HP-UX 11.0 and 11.11, when configured as a print server, allows local users to overwrite arbitrary files by modifying certain resources. | Modified (20090302) | ACCEPT(4) Armstrong, Bishop, Cole, Foat | NOOP(1) Wall | REJECT(1) Frech | Frech> See XF:samba-tmpfile-symlink(6396). | Discovery and advisory are two months apart, and no other Samba | issues seem to exist around that timespan. | View |
8482 | CVE-2004-0054 | Candidate | Multiple vulnerabilities in the H.323 protocol implementation for Cisco IOS 11.3T through 12.2T allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol. | Modified (20090302) | ACCEPT(5) Armstrong, Baker, Cole, Green, Wall | NOOP(1) Cox | View |
Page 20503 of 20943, showing 5 records out of 104715 total, starting on record 102511, ending on 102515