CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7341  CVE-2003-0514  Candidate  Apple Safari allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Safari to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.  Proposed (20040318)  ACCEPT(4) Armstrong, Baker, Balinsky, Cole | MODIFY(1) Frech | NOOP(2) Cox, Wall | REVIEWING(1) Christey  Frech> XF:web-browser-cookie-bypass(15424) | http://xforce.iss.net/xforce/xfdb/15424 | Christey> Consider whether this is really a design-level problem that applies to | the interaction between any vulnerable XSS, its associated domain, and | any web browser, because browsers enforce security boundaries at the | domain level. If so, then the "%2e%2e" problem may be a red herring, | or a single attack vector of any number of vectors. | | CVE-2003-0513, CVE-2003-0514, CVE-2003-0592, CVE-2003-0593, | and CVE-2003-0594 all cover this specific issue (each for a | different browser).  View
8645  CVE-2004-0217  Candidate  The LiveUpdate capability (liveupdate.sh) in Symantec AntiVirus Scan Engine 4.0 and 4.3 for Red Hat Linux allows local users to create or append to arbitrary files via a symlink attack on /tmp/LiveUpdate.log.  Proposed (20040318)  ACCEPT(2) Armstrong, Cole | MODIFY(1) Frech | NOOP(1) Cox | REVIEWING(1) Wall  Frech> XF:symantec-scanengine-race-condition(15215) | http://xforce.iss.net/xforce/xfdb/15215  View
8666  CVE-2004-0238  Candidate  Multiple buffer overflows in Overkill (0verkill) 0.15pre3 might allow local users to execute arbitrary code in the client via a long HOME environment variable in the (1) load_cfg and (2) save_cfg functions; possibly allow remote attackers to execute arbitrary code via long strings to (3) the send_message function; and, in the server, via (4) the parse_command_line function.  Proposed (20040318)  ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall    View
8667  CVE-2004-0239  Candidate  SQL injection vulnerability in showphoto.php in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain unauthorized access via the photo variable.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8668  CVE-2004-0240  Candidate  Directory traversal vulnerability in X-Cart 3.4.3 allows remote attackers to view arbitrary files via a .. (dot dot) in the shop_closed_file argument to auth.php.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View

Page 20939 of 20943, showing 5 records out of 104715 total, starting on record 104691, ending on 104695

Actions