CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8681 | CVE-2004-0253 | Candidate | IBM Cloudscape 5.1 running jdk 1.4.2_03 allows remote attackers to execute arbitrary programs or cause a denial of service via certain SQL code, possibly due to a SQL injection vulnerability. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8682 | CVE-2004-0254 | Candidate | Cross-site scripting (XSS) vulnerability in Discuz! Board 2.x and 3.x allows remote attackers to execute arbitrary script as other users via an img tag. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8683 | CVE-2004-0255 | Candidate | Xlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long directory consisting of . (dot) and / (slash) characters, which causes the server to crash when the administrator views the log file, possibly triggering a buffer overflow. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | REVIEWING(1) Christey | Christey> MISC:http://www.xlightftpd.com/forum/viewtopic.php?t=40 | In the above URL, the vendor says that only one of 3 bugs | reported in February 2004 were an "actual server bug," and the other 2 | "traced back into windows" dll and they won"t happen if windows | service pack is installed. | | The "actual server bug" is CVE-2004-0287. The demonstration | for *this* issue shows that the application breaks in comctl32.dll. | So, this candidate may be erroneous, and an interesting side effect of | another bug that"s not related to xlight at all. | | Thus, this candidate may need to be REJECTED. | View |
8430 | CVE-2004-0002 | Candidate | The TCP MSS (maximum segment size) functionality in netinet allows remote attackers to cause a denial of service (resource exhaustion) via (1) a low MTU, which causes a large number of small packets to be produced, or (2) via a large number of packets with a small TCP payload, which cause a large number of calls to the resource-intensive sowakeup function. | Proposed (20040318) | ACCEPT(4) Armstrong, Baker, Cole, Williams | NOOP(2) Cox, Wall | View | |
8686 | CVE-2004-0258 | Candidate | Multiple buffer overflows in RealOne Player, RealOne Player 2.0, RealOne Enterprise Desktop, and RealPlayer Enterprise allow remote attackers to execute arbitrary code via malformed (1) .RP, (2) .RT, (3) .RAM, (4) .RPM or (5) .SMIL files. | Proposed (20040318) | ACCEPT(4) Armstrong, Baker, Cole, Wall | NOOP(1) Cox | View |
Page 20941 of 20943, showing 5 records out of 104715 total, starting on record 104701, ending on 104705