CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7110  CVE-2003-0282  Candidate  Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.  Assigned (20030512)  None (candidate not yet proposed)    View
7111  CVE-2003-0283  Candidate  Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a message with a "<<" before a tag name in the (1) subject, (2) author"s name, or (3) author"s e-mail.  Assigned (20030512)  None (candidate not yet proposed)    View
7112  CVE-2003-0284  Candidate  Adobe Acrobat 5 does not properly validate JavaScript in PDF files, which allows remote attackers to write arbitrary files into the Plug-ins folder that spread to other PDF documents, as demonstrated by the W32.Yourde virus.  Assigned (20030513)  None (candidate not yet proposed)    View
7113  CVE-2003-0285  Candidate  IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, which allows Sendmail to be used as an open mail relay for sending spam e-mail.  Assigned (20030513)  None (candidate not yet proposed)    View
7114  CVE-2003-0286  Candidate  SQL injection vulnerability in register.asp in Snitz Forums 2000 before 3.4.03, and possibly 3.4.07 and earlier, allows remote attackers to execute arbitrary stored procedures via the Email variable.  Assigned (20030513)  None (candidate not yet proposed)    View

Page 671 of 20943, showing 5 records out of 104715 total, starting on record 3351, ending on 3355

Actions