CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8499  CVE-2004-0071  Candidate  Directory traversal vulnerability in buildManPage in class.manpagelookup.php for PHP Man Page Lookup 1.2.0 allows remote attackers to read arbitrary files via the command parameter ($cmd variable) to index.php.  Modified (20071113)  ACCEPT(2) Armstrong, Baker | MODIFY(1) Williams | NOOP(3) Cole, Cox, Wall  Williams> contacted vendor. affects v1.2.0. fixed in v1.3.0. | http://php.amnuts.com/index.php?do=fdload&id=1&file=class.manpagelookup.php | http://php.amnuts.com/forums/viewtopic.php?t=70  View
8502  CVE-2004-0074  Candidate  Multiple buffer overflows in xsok 1.02 allows local users to gain privileges via (1) a long LANG environment variable, or (2) a long -xsokdir command line argument, a different vulnerability than CVE-2003-0949.  Proposed (20040318)  ACCEPT(3) Armstrong, Baker, Williams | NOOP(3) Cole, Cox, Wall  Williams> DSA-405-1  View
8471  CVE-2004-0043  Candidate  Buffer overflow in Yahoo Instant Messenger 5.6.0.1351 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in the download feature.  Modified (20071113)  ACCEPT(3) Armstrong, Baker, Williams | NOOP(2) Cole, Cox | REVIEWING(1) Wall  Williams> http://lists.netsys.com/pipermail/full-disclosure/2004-January/015355.html | http://www.packetstormsecurity.nl/0401-advisories/yahooIM.txt  View
8458  CVE-2004-0030  Candidate  PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains the code.  Modified (20071113)  ACCEPT(3) Armstrong, Baker, Williams | NOOP(3) Cole, Cox, Wall  Williams> http://phpgedview.sourceforge.net/  View
8493  CVE-2004-0065  Candidate  Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2) placelist.php.  Modified (20071113)  ACCEPT(4) Armstrong, Baker, Cole, Williams | NOOP(2) Cox, Wall  Williams> http://sourceforge.net/project/showfiles.php?group_id=55456  View

Page 20939 of 20943, showing 5 records out of 104715 total, starting on record 104691, ending on 104695

Actions