CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9739  CVE-2004-1311  Candidate  Integer overflow in the real_setup_and_get_header function in real.c for Unix MPlayer 1.0pre5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a Real RTSP streaming media file with a -1 content-length field, which leads to a heap-based buffer overflow.  Assigned (20041221)  None (candidate not yet proposed)    View
9740  CVE-2004-1312  Candidate  A bug in the HTML parser in a certain Microsoft HTML library, as used in various third party products, may allow remote attackers to cause a denial of service via certain strings, as reported in GFI MailEssentials for Exchange 9 and 10, and GFI MailSecurity for Exchange 8, which causes emails to remain in IIS or Exchange mail queues.  Assigned (20041221)  None (candidate not yet proposed)    View
9741  CVE-2004-1313  Candidate  The Smc.exe process in My Firewall Plus 5.0 build 1117, and possibly other versions, does not drop privileges before invoking help, which allows local users to gain privileges.  Assigned (20041221)  None (candidate not yet proposed)    View
9742  CVE-2004-1314  Candidate  Safari 1.x allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability, a different vulnerability than CVE-2004-1122.  Assigned (20041221)  None (candidate not yet proposed)    View
9724  CVE-2004-1296  Candidate  The (1) eqn2graph and (2) pic2graph scripts in groff 1.18.1 allow local users to overwrite arbitrary files via a symlink attack on temporary files.  Assigned (20041221)  None (candidate not yet proposed)    View

Page 1038 of 20943, showing 5 records out of 104715 total, starting on record 5186, ending on 5190

Actions