CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9299  CVE-2004-0871  Candidate  Mozilla does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie Injection."  Assigned (20040914)  None (candidate not yet proposed)    View
9300  CVE-2004-0872  Candidate  Opera does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie Injection."  Assigned (20040914)  None (candidate not yet proposed)    View
9301  CVE-2004-0873  Candidate  Apple iChat AV 2.1, AV 2.0, and 1.0.1 allows remote attackers to execute arbitrary programs via a "link" that references the program.  Assigned (20040916)  None (candidate not yet proposed)    View
9302  CVE-2004-0874  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-1123. Reason: This candidate is a reservation duplicate of CVE-2004-1123. Notes: All CVE users should reference CVE-2004-1123 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20040917)  None (candidate not yet proposed)    View
9303  CVE-2004-0875  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware (aka webdistro) 0.9.16.002 and earlier allow remote attackers to insert arbitrary HTML or web script, as demonstrated with a request to the wiki module.  Assigned (20040917)  None (candidate not yet proposed)    View

Page 950 of 20943, showing 5 records out of 104715 total, starting on record 4746, ending on 4750

Actions