CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1798 | CVE-2000-0220 | Candidate | ZoneAlarm sends sensitive system and network information in cleartext to the Zone Labs server if a user requests more information about an event. | Proposed (20000322) | ACCEPT(1) Armstrong | MODIFY(1) Frech | NOOP(5) Baker, Cole, LeBlanc, Ozancin, Wall | REJECT(1) Blake | REVIEWING(1) Levy | Blake> Discussion on Bugtraq shows that this is a really marginal issue. Very | tough to come up with a viable attack scenario. Also, it"s part of how | this class of software works, not a flaw in the cited package. Might be | possible to recast this into something more generic.... | Frech> XF:zonealarm-exposes-info | View |
5888 | CVE-2002-1504 | Candidate | Directory traversal vulnerability in WebServer 4 Everyone 1.22 allows remote attackers to read arbitrary files via ".." (dot-dot backslash) sequences in a URL. | Proposed (20030317) | ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall | View | |
8741 | CVE-2004-0313 | Candidate | Buffer overflow in PSOProxy 0.91 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP request, as demonstrated using a long (1) GET argument or (2) method name. | Proposed (20040318) | ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall | View | |
8750 | CVE-2004-0322 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to execute arbitrary script as other users via the (1) member parameter in member.php, (2) uid parameter in u2uadmin.php, (3) user parameter in editprofile.php, (4) an onmouseover event in an align tag when bbcode is allowed, or (5) img tag where bbcode is allowed. | Modified (20050718) | ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall | View | |
8751 | CVE-2004-0323 | Candidate | Multiple SQL injection vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to inject arbitrary SQL and gain privileges via the (1) ppp parameter in viewthread.php, (2) desc parameter in misc.php, (3) tpp parameter in forumdisplay.php, (4) ascdesc parameter in forumdisplay.php, or (5) the addon parameter in stats.php. NOTE: it has also been shown that item (3) is also in XMB 1.9 beta. | Modified (20051128) | ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall | View |
Page 612 of 20943, showing 5 records out of 104715 total, starting on record 3056, ending on 3060