CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5183  CVE-2002-0793  Candidate  Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrite arbitrary files via (1) the -f argument to the monitor utility, (2) the -d argument to dumper, (3) the -c argument to crttrap, or (4) using the Watcom sample utility.  Modified (20050528)  NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
5189  CVE-2002-0799  Candidate  Buffer overflow in YoungZSoft CMailServer 3.30 allows remote attackers to execute arbitrary code via a long USER argument.  Proposed (20020726)  NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
8715  CVE-2004-0287  Candidate  Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a large number of / (slash) characters, possibly triggering a buffer overflow.  Modified (20050518)  NOOP(5) Armstrong, Christey, Cole, Cox, Wall  Christey> CONFIRM:http://xlightftpd.com/forum/viewtopic.php?t=32 | and http://www.xlightftpd.com/forum/viewtopic.php?t=40 says | that this was fixed in 1.55. | | Also, DELREF BID:9627 - it"s not a clean match. | Instead, ADDREF BID:9668  View
8738  CVE-2004-0310  Candidate  Cross-site scripting (XSS) vulnerability in LiveJournal 1.0 and 1.1 allows remote attackers to execute Javascript as other users via the stylesheet, which does not strip the semicolon or parentheses, as demonstrated using a background:url.  Proposed (20040318)  NOOP(5) Armstrong, Christey, Cole, Cox, Wall  Christey> Despite the description, the specific affected versions are | not actually known. Either they need to be removed or we need | some source that can confirm the affected versions.  View
8762  CVE-2004-0334  Candidate  InnoMedia VideoPhone allows remote attackers to bypass Basic Authorization via an HTTP request to (1) videophone_admindetail.asp, (2) videophone_syscfg.asp, (3) videophone_upgrade.asp, or (4) videophone_sysctrl.asp that contains a trailing / (slash). NOTE: the original report mentioned AXIS 2100 Network Camera, but this was likely a cut-and-paste error.  Modified (20060816)  NOOP(5) Armstrong, Christey, Cole, Cox, Wall  Christey> According to SecurityTracker.com, the initial advisory | erroneously mentions Axis 1200: | MISC:http://securitytracker.com/alerts/2004/Mar/1009522.html  View

Page 7 of 20943, showing 5 records out of 104715 total, starting on record 31, ending on 35

<<first 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 last>>

Actions