CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9613 | CVE-2004-1185 | Candidate | Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames. | Assigned (20041213) | None (candidate not yet proposed) | View | |
9614 | CVE-2004-1186 | Candidate | Multiple buffer overflows in enscript 1.6.3 allow remote attackers or local users to cause a denial of service (application crash). | Assigned (20041213) | None (candidate not yet proposed) | View | |
9615 | CVE-2004-1187 | Candidate | Heap-based buffer overflow in the pnm_get_chunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote attackers to execute arbitrary code via long PNA_TAG values, a different vulnerability than CVE-2004-1188. | Assigned (20041213) | None (candidate not yet proposed) | View | |
9616 | CVE-2004-1188 | Candidate | The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the chunk size is less than the PREAMBLE_SIZE, which causes a read operation with a negative length that leads to a buffer overflow via (1) RMF_TAG, (2) DATA_TAG, (3) PROP_TAG, (4) MDPR_TAG, and (5) CONT_TAG values, a different vulnerability than CVE-2004-1187. | Assigned (20041213) | None (candidate not yet proposed) | View | |
9617 | CVE-2004-1189 | Candidate | The add_to_history function in svr_principal.c in libkadm5srv for MIT Kerberos 5 (krb5) up to 1.3.5, when performing a password change, does not properly track the password policy"s history count and the maximum number of keys, which can cause an array index out-of-bounds error and may allow authenticated users to execute arbitrary code via a heap-based buffer overflow. | Assigned (20041213) | None (candidate not yet proposed) | View |
Page 1013 of 20943, showing 5 records out of 104715 total, starting on record 5061, ending on 5065