CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8715  CVE-2004-0287  Candidate  Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a large number of / (slash) characters, possibly triggering a buffer overflow.  Modified (20050518)  NOOP(5) Armstrong, Christey, Cole, Cox, Wall  Christey> CONFIRM:http://xlightftpd.com/forum/viewtopic.php?t=32 | and http://www.xlightftpd.com/forum/viewtopic.php?t=40 says | that this was fixed in 1.55. | | Also, DELREF BID:9627 - it"s not a clean match. | Instead, ADDREF BID:9668  View
8738  CVE-2004-0310  Candidate  Cross-site scripting (XSS) vulnerability in LiveJournal 1.0 and 1.1 allows remote attackers to execute Javascript as other users via the stylesheet, which does not strip the semicolon or parentheses, as demonstrated using a background:url.  Proposed (20040318)  NOOP(5) Armstrong, Christey, Cole, Cox, Wall  Christey> Despite the description, the specific affected versions are | not actually known. Either they need to be removed or we need | some source that can confirm the affected versions.  View
8762  CVE-2004-0334  Candidate  InnoMedia VideoPhone allows remote attackers to bypass Basic Authorization via an HTTP request to (1) videophone_admindetail.asp, (2) videophone_syscfg.asp, (3) videophone_upgrade.asp, or (4) videophone_sysctrl.asp that contains a trailing / (slash). NOTE: the original report mentioned AXIS 2100 Network Camera, but this was likely a cut-and-paste error.  Modified (20060816)  NOOP(5) Armstrong, Christey, Cole, Cox, Wall  Christey> According to SecurityTracker.com, the initial advisory | erroneously mentions Axis 1200: | MISC:http://securitytracker.com/alerts/2004/Mar/1009522.html  View
5120  CVE-2002-0730  Candidate  Cross-site scripting vulnerability in guestbook.pl for Philip Chinery"s Guestbook 1.1 allows remote attackers to execute Javascript or HTML via fields such as (1) Name, (2) EMail, or (3) Homepage.  Proposed (20020726)  NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
5129  CVE-2002-0739  Candidate  Cross-site scripting in PostCalendar 3.02 allows remote attackers to insert arbitrary HTML and script, and steal cookies, by modifying a calendar entry in its preview page.  Proposed (20020726)  NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View

Page 20937 of 20943, showing 5 records out of 104715 total, starting on record 104681, ending on 104685

Actions