NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 72011 | CVE-2004-1632 | Cross-site scripting (XSS) vulnerability in wiki.php in MoniWiki 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the arguments to wiki.php. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72012 | CVE-2004-1633 | process_bug.cgi in Bugzilla 2.9 through 2.18rc2 and 2.19 from CVS does not check edit permissions on the keywords field, which allows remote authenticated users to modify the keywords in a bug via the keywordaction parameter. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72013 | CVE-2004-1634 | show_bug.cgi in Bugzilla 2.17.1 through 2.18rc2 and 2.19 from CVS, when using the insidergroup feature and exporting a bug to XML, shows comments and attachment summaries which are marked as private, which allows remote attackers to gain sensitive information. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72014 | CVE-2004-1635 | Bugzilla 2.17.1 through 2.18rc2 and 2.19 from cvs, when using the insidergroup feature, does not sufficiently protect private attachments when there are changes to the metadata, such as filename, description, MIME type, or review flags, which allows remote authenticated users to obtain sensitive information when (1) viewing the bug activity log or (2) receiving bug change notification mails. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72015 | CVE-2004-1636 | Heap-based buffer overflow in the WvTFTPServer::new_connection function in wvtftpserver.cc for WvTftp 0.9 allows remote attackers to execute arbitrary code via a long option string in a TFTP packet. | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View |
Page 1955 of 17672, showing 5 records out of 88360 total, starting on record 9771, ending on 9775