CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8786  CVE-2004-0358  Candidate  Cross-site scripting (XSS) vulnerability in VirtuaNews Admin Panel Pro 1.0.3 allows remote attackers to execute arbitrary script as other users via (1) the mainnews parameter in admin.php, (2) the expand parameter in admin.php, (3) the id parameter in admin.php, (4) the catid parameter in admin.php, or (5) an unnamed parameter during the newslogo_upload action in admin.php.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8788  CVE-2004-0360  Candidate  Unknown vulnerability in passwd(1) in Solaris 8.0 and 9.0 allows local users to gain privileges via unknown attack vectors.  Proposed (20040318)  ACCEPT(4) Armstrong, Baker, Cole, Wall | NOOP(1) Cox    View
8789  CVE-2004-0361  Candidate  The Javascript engine in Safari 1.2 and earlier allows remote attackers to cause a denial of service (segmentation fault) by creating a new Array object with a large size value, then writing into that array.  Proposed (20040318)  ACCEPT(2) Armstrong, Cole | NOOP(2) Cox, Wall    View
8586  CVE-2004-0158  Candidate  Buffer overflow in lbreakout2 allows local users to gain "games" group privileges via a large HOME environment variable to (1) editor.c, (2) theme.c, (3) manager.c, (4) config.c, (5) game.c, (6) levels.c, or (7) main.c.  Proposed (20040318)  ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall    View
7340  CVE-2003-0513  Candidate  Microsoft Internet Explorer allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Internet Explorer to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.  Proposed (20040318)  ACCEPT(5) Armstrong, Baker, Balinsky, Cole, Green | MODIFY(1) Frech | NOOP(1) Cox | REVIEWING(2) Christey, Wall  Frech> XF:web-browser-cookie-bypass(15424) | http://xforce.iss.net/xforce/xfdb/15424 | Christey> Consider whether this is really a design-level problem that applies to | the interaction between any vulnerable XSS, its associated domain, and | any web browser, because browsers enforce security boundaries at the | domain level. If so, then the "%2e%2e" problem may be a red herring, | or a single attack vector of any number of vectors. | | CVE-2003-0513, CVE-2003-0514, CVE-2003-0592, CVE-2003-0593, | and CVE-2003-0594 all cover this specific issue (each for a | different browser).  View

Page 20938 of 20943, showing 5 records out of 104715 total, starting on record 104686, ending on 104690

Actions