CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
53307 | CVE-2012-0064 | Candidate | xkeyboard-config before 2.5 in X.Org before 7.6 enables certain XKB debugging functions by default, which allows physically proximate attackers to bypass an X screen lock via keyboard combinations that break the input grab. | Assigned (20111207) | None (candidate not yet proposed) | View | |
8683 | CVE-2004-0255 | Candidate | Xlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long directory consisting of . (dot) and / (slash) characters, which causes the server to crash when the administrator views the log file, possibly triggering a buffer overflow. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | REVIEWING(1) Christey | Christey> MISC:http://www.xlightftpd.com/forum/viewtopic.php?t=40 | In the above URL, the vendor says that only one of 3 bugs | reported in February 2004 were an "actual server bug," and the other 2 | "traced back into windows" dll and they won"t happen if windows | service pack is installed. | | The "actual server bug" is CVE-2004-0287. The demonstration | for *this* issue shows that the application breaks in comctl32.dll. | So, this candidate may be erroneous, and an interesting side effect of | another bug that"s not related to xlight at all. | | Thus, this candidate may need to be REJECTED. | View |
8715 | CVE-2004-0287 | Candidate | Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a large number of / (slash) characters, possibly triggering a buffer overflow. | Modified (20050518) | NOOP(5) Armstrong, Christey, Cole, Cox, Wall | Christey> CONFIRM:http://xlightftpd.com/forum/viewtopic.php?t=32 | and http://www.xlightftpd.com/forum/viewtopic.php?t=40 says | that this was fixed in 1.55. | | Also, DELREF BID:9627 - it"s not a clean match. | Instead, ADDREF BID:9668 | View |
22060 | CVE-2006-5956 | Candidate | XLineSoft PHPRunner 3.1 stores the (1) database server name, (2) database names, (3) usernames, and (4) passwords in plaintext in %WINDIR%PHPRunner.ini, which allows local users to obtain sensitive information by reading the file. | Assigned (20061116) | None (candidate not yet proposed) | View | |
11844 | CVE-2005-0638 | Candidate | xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly quoted when calling the gunzip command. | Assigned (20050304) | None (candidate not yet proposed) | View |
Page 20863 of 20943, showing 5 records out of 104715 total, starting on record 104311, ending on 104315