CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1798  CVE-2000-0220  Candidate  ZoneAlarm sends sensitive system and network information in cleartext to the Zone Labs server if a user requests more information about an event.  Proposed (20000322)  ACCEPT(1) Armstrong | MODIFY(1) Frech | NOOP(5) Baker, Cole, LeBlanc, Ozancin, Wall | REJECT(1) Blake | REVIEWING(1) Levy  Blake> Discussion on Bugtraq shows that this is a really marginal issue. Very | tough to come up with a viable attack scenario. Also, it"s part of how | this class of software works, not a flaw in the cited package. Might be | possible to recast this into something more generic.... | Frech> XF:zonealarm-exposes-info  View
5888  CVE-2002-1504  Candidate  Directory traversal vulnerability in WebServer 4 Everyone 1.22 allows remote attackers to read arbitrary files via ".." (dot-dot backslash) sequences in a URL.  Proposed (20030317)  ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall    View
8741  CVE-2004-0313  Candidate  Buffer overflow in PSOProxy 0.91 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP request, as demonstrated using a long (1) GET argument or (2) method name.  Proposed (20040318)  ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall    View
8750  CVE-2004-0322  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to execute arbitrary script as other users via the (1) member parameter in member.php, (2) uid parameter in u2uadmin.php, (3) user parameter in editprofile.php, (4) an onmouseover event in an align tag when bbcode is allowed, or (5) img tag where bbcode is allowed.  Modified (20050718)  ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall    View
8751  CVE-2004-0323  Candidate  Multiple SQL injection vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to inject arbitrary SQL and gain privileges via the (1) ppp parameter in viewthread.php, (2) desc parameter in misc.php, (3) tpp parameter in forumdisplay.php, (4) ascdesc parameter in forumdisplay.php, or (5) the addon parameter in stats.php. NOTE: it has also been shown that item (3) is also in XMB 1.9 beta.  Modified (20051128)  ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall    View

Page 612 of 20943, showing 5 records out of 104715 total, starting on record 3056, ending on 3060

Actions