CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8652 | CVE-2004-0224 | Candidate | Multiple buffer overflows in (1) iso2022jp.c or (2) shiftjis.c for Courier-IMAP before 3.0.0, Courier before 0.45, and SqWebMail before 4.0.0 may allow remote attackers to execute arbitrary code "when Unicode character is out of BMP range." | Modified (20050719) | ACCEPT(4) Armstrong, Baker, Cole, Cox | MODIFY(1) Frech | NOOP(3) Christey, Green, Wall | Frech> XF:courier-codeset-converter-bo(15434) | http://xforce.iss.net/xforce/xfdb/15434 | Christey> BUGTRAQ:20040329 [ GLSA 200403-06 ] Multiple remote buffer overflow vulnerabilities in Courier | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108058112903373&w=2 | Christey> BUGTRAQ:20040329 [ GLSA 200403-06 ] Multiple remote buffer overflow vulnerabilities in Courier | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108058112903373&w=2 | Christey> MISC:http://www.debian.org/security/nonvulns-woody#CVE-2004-0075 | CHANGE> [Cox changed vote from REVIEWING to ACCEPT] | View |
8750 | CVE-2004-0322 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to execute arbitrary script as other users via the (1) member parameter in member.php, (2) uid parameter in u2uadmin.php, (3) user parameter in editprofile.php, (4) an onmouseover event in an align tag when bbcode is allowed, or (5) img tag where bbcode is allowed. | Modified (20050718) | ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall | View | |
8770 | CVE-2004-0342 | Candidate | WFTPD Pro Server 3.21 Release 1, with the XeroxDocutech option enabled, allows local users to cause a denial of service (crash) via a (1) MKD or (2) XMKD command that causes an absolute path of 260 characters to be used, which overwrites a cookie with a null character, possibly due to an off-by-one error. | Modified (20050718) | ACCEPT(2) Armstrong, Wall | NOOP(2) Cole, Cox | View | |
4673 | CVE-2002-0281 | Candidate | Cross-site scripting vulnerability in DCP-Portal 4.2 and earlier allows remote attackers to gain privileges of other portal users by providing Javascript in the job information field to user_update.php. | Modified (20050710) | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | Frech> XF:dcpportal-userupdate-css(8197) | View |
4674 | CVE-2002-0282 | Candidate | DCP-Portal 3.7 through 4.5 allows remote attackers to obtain the physical path of the server via (1) a direct request to add_user.php, or via an invalid new_language parameter in (2) contents.php, (3) categories.php, or (4) files.php, which leaks the path in an error message. | Modified (20050710) | ACCEPT(2) Cole, Frech | NOOP(4) Armstrong, Cox, Foat, Wall | View |
Page 497 of 20943, showing 5 records out of 104715 total, starting on record 2481, ending on 2485