CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
7341 | CVE-2003-0514 | Candidate | Apple Safari allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Safari to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application. | Proposed (20040318) | ACCEPT(4) Armstrong, Baker, Balinsky, Cole | MODIFY(1) Frech | NOOP(2) Cox, Wall | REVIEWING(1) Christey | Frech> XF:web-browser-cookie-bypass(15424) | http://xforce.iss.net/xforce/xfdb/15424 | Christey> Consider whether this is really a design-level problem that applies to | the interaction between any vulnerable XSS, its associated domain, and | any web browser, because browsers enforce security boundaries at the | domain level. If so, then the "%2e%2e" problem may be a red herring, | or a single attack vector of any number of vectors. | | CVE-2003-0513, CVE-2003-0514, CVE-2003-0592, CVE-2003-0593, | and CVE-2003-0594 all cover this specific issue (each for a | different browser). | View |
8645 | CVE-2004-0217 | Candidate | The LiveUpdate capability (liveupdate.sh) in Symantec AntiVirus Scan Engine 4.0 and 4.3 for Red Hat Linux allows local users to create or append to arbitrary files via a symlink attack on /tmp/LiveUpdate.log. | Proposed (20040318) | ACCEPT(2) Armstrong, Cole | MODIFY(1) Frech | NOOP(1) Cox | REVIEWING(1) Wall | Frech> XF:symantec-scanengine-race-condition(15215) | http://xforce.iss.net/xforce/xfdb/15215 | View |
8666 | CVE-2004-0238 | Candidate | Multiple buffer overflows in Overkill (0verkill) 0.15pre3 might allow local users to execute arbitrary code in the client via a long HOME environment variable in the (1) load_cfg and (2) save_cfg functions; possibly allow remote attackers to execute arbitrary code via long strings to (3) the send_message function; and, in the server, via (4) the parse_command_line function. | Proposed (20040318) | ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall | View | |
8667 | CVE-2004-0239 | Candidate | SQL injection vulnerability in showphoto.php in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain unauthorized access via the photo variable. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8668 | CVE-2004-0240 | Candidate | Directory traversal vulnerability in X-Cart 3.4.3 allows remote attackers to view arbitrary files via a .. (dot dot) in the shop_closed_file argument to auth.php. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View |
Page 20939 of 20943, showing 5 records out of 104715 total, starting on record 104691, ending on 104695