CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
810 | CVE-1999-0830 | Candidate | Buffer overflow in SCO UnixWare Xsco command via a long argument. | Proposed (19991208) | ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(3) Cole, Frech, Prosser | REVIEWING(1) Christey | Cole> This is BID 824 and the BUGTRAQ reference is 19991125. | Frech> XF:sco-unixware-xsco | Christey> Confirmed by vendor, albeit vaguely: | http://marc.theaimsgroup.com/?l=bugtraq&m=94581379905584&w=2 | | Prosser> agree with Steve on vendor confirmation, however not sure the | fix ref"d in BID 824 (SSE041) is right. It lists fixes for libnsl and | tcpip.so, nothing about xsco. SSE050b | (ftp://ftp.sco.com/SSE/security_bulletins/SB-99.26b) fixes a buffer overflow | in xsco on OpenServer (the vendor message Steve refers to) but not the | UnixWare vulnerability reported on Bugtraq and in BID824. Anyone more | familar with SCO shed some light on this? Are they the same codebase so fix | would be same? From the SCO site it seems the UnixWare and OpenSever | products are similar but have differences. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> BID:824 | http://www.securityfocus.com/bid/824 | View |
8471 | CVE-2004-0043 | Candidate | Buffer overflow in Yahoo Instant Messenger 5.6.0.1351 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in the download feature. | Modified (20071113) | ACCEPT(3) Armstrong, Baker, Williams | NOOP(2) Cole, Cox | REVIEWING(1) Wall | Williams> http://lists.netsys.com/pipermail/full-disclosure/2004-January/015355.html | http://www.packetstormsecurity.nl/0401-advisories/yahooIM.txt | View |
8458 | CVE-2004-0030 | Candidate | PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains the code. | Modified (20071113) | ACCEPT(3) Armstrong, Baker, Williams | NOOP(3) Cole, Cox, Wall | Williams> http://phpgedview.sourceforge.net/ | View |
8494 | CVE-2004-0066 | Candidate | phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (2) famlist.php, (3) placelist.php, (4) imageview.php, (5) timeline.php, (6) clippings.php, (7) login.php, and (8) gdbi.php. | Modified (20071113) | ACCEPT(3) Armstrong, Baker, Williams | NOOP(3) Cole, Cox, Wall | Williams> http://sourceforge.net/project/showfiles.php?group_id=55456 | View |
8495 | CVE-2004-0067 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7) imageview.php, (8) calendar.php, (9) gedrecord.php, (10) login.php, and (11) gdbi_interface.php. NOTE: some aspects of vector 10 were later reported to affect 4.1. | Modified (20090127) | ACCEPT(3) Armstrong, Baker, Williams | NOOP(3) Cole, Cox, Wall | Williams> http://sourceforge.net/project/showfiles.php?group_id=55456 | View |
Page 907 of 20943, showing 5 records out of 104715 total, starting on record 4531, ending on 4535