CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5183 | CVE-2002-0793 | Candidate | Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrite arbitrary files via (1) the -f argument to the monitor utility, (2) the -d argument to dumper, (3) the -c argument to crttrap, or (4) using the Watcom sample utility. | Modified (20050528) | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | View | |
5189 | CVE-2002-0799 | Candidate | Buffer overflow in YoungZSoft CMailServer 3.30 allows remote attackers to execute arbitrary code via a long USER argument. | Proposed (20020726) | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | View | |
8715 | CVE-2004-0287 | Candidate | Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a large number of / (slash) characters, possibly triggering a buffer overflow. | Modified (20050518) | NOOP(5) Armstrong, Christey, Cole, Cox, Wall | Christey> CONFIRM:http://xlightftpd.com/forum/viewtopic.php?t=32 | and http://www.xlightftpd.com/forum/viewtopic.php?t=40 says | that this was fixed in 1.55. | | Also, DELREF BID:9627 - it"s not a clean match. | Instead, ADDREF BID:9668 | View |
8738 | CVE-2004-0310 | Candidate | Cross-site scripting (XSS) vulnerability in LiveJournal 1.0 and 1.1 allows remote attackers to execute Javascript as other users via the stylesheet, which does not strip the semicolon or parentheses, as demonstrated using a background:url. | Proposed (20040318) | NOOP(5) Armstrong, Christey, Cole, Cox, Wall | Christey> Despite the description, the specific affected versions are | not actually known. Either they need to be removed or we need | some source that can confirm the affected versions. | View |
8762 | CVE-2004-0334 | Candidate | InnoMedia VideoPhone allows remote attackers to bypass Basic Authorization via an HTTP request to (1) videophone_admindetail.asp, (2) videophone_syscfg.asp, (3) videophone_upgrade.asp, or (4) videophone_sysctrl.asp that contains a trailing / (slash). NOTE: the original report mentioned AXIS 2100 Network Camera, but this was likely a cut-and-paste error. | Modified (20060816) | NOOP(5) Armstrong, Christey, Cole, Cox, Wall | Christey> According to SecurityTracker.com, the initial advisory | erroneously mentions Axis 1200: | MISC:http://securitytracker.com/alerts/2004/Mar/1009522.html | View |
Page 7 of 20943, showing 5 records out of 104715 total, starting on record 31, ending on 35