CVE List

Id CVE No. Status Description Phase Votes Comments Actions
53307  CVE-2012-0064  Candidate  xkeyboard-config before 2.5 in X.Org before 7.6 enables certain XKB debugging functions by default, which allows physically proximate attackers to bypass an X screen lock via keyboard combinations that break the input grab.  Assigned (20111207)  None (candidate not yet proposed)    View
8683  CVE-2004-0255  Candidate  Xlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long directory consisting of . (dot) and / (slash) characters, which causes the server to crash when the administrator views the log file, possibly triggering a buffer overflow.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall | REVIEWING(1) Christey  Christey> MISC:http://www.xlightftpd.com/forum/viewtopic.php?t=40 | In the above URL, the vendor says that only one of 3 bugs | reported in February 2004 were an "actual server bug," and the other 2 | "traced back into windows" dll and they won"t happen if windows | service pack is installed. | | The "actual server bug" is CVE-2004-0287. The demonstration | for *this* issue shows that the application breaks in comctl32.dll. | So, this candidate may be erroneous, and an interesting side effect of | another bug that"s not related to xlight at all. | | Thus, this candidate may need to be REJECTED.  View
8715  CVE-2004-0287  Candidate  Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a large number of / (slash) characters, possibly triggering a buffer overflow.  Modified (20050518)  NOOP(5) Armstrong, Christey, Cole, Cox, Wall  Christey> CONFIRM:http://xlightftpd.com/forum/viewtopic.php?t=32 | and http://www.xlightftpd.com/forum/viewtopic.php?t=40 says | that this was fixed in 1.55. | | Also, DELREF BID:9627 - it"s not a clean match. | Instead, ADDREF BID:9668  View
22060  CVE-2006-5956  Candidate  XLineSoft PHPRunner 3.1 stores the (1) database server name, (2) database names, (3) usernames, and (4) passwords in plaintext in %WINDIR%PHPRunner.ini, which allows local users to obtain sensitive information by reading the file.  Assigned (20061116)  None (candidate not yet proposed)    View
11844  CVE-2005-0638  Candidate  xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly quoted when calling the gunzip command.  Assigned (20050304)  None (candidate not yet proposed)    View

Page 20863 of 20943, showing 5 records out of 104715 total, starting on record 104311, ending on 104315

Actions