CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9879  CVE-2004-1451  Candidate  Mozilla before 1.6 does not display the entire URL in the status bar when a link contains %00, which could allow remote attackers to trick users into clicking on unknown or untrusted sites and facilitate phishing attacks.  Assigned (20050213)  None (candidate not yet proposed)    View
9880  CVE-2004-1452  Candidate  Tomcat before 5.0.27-r3 in Gentoo Linux sets the default permissions on the init scripts as tomcat:tomcat, but executes the scripts with root privileges, which could allow local users in the tomcat group to execute arbitrary commands as root by modifying the scripts.  Assigned (20050213)  None (candidate not yet proposed)    View
9881  CVE-2004-1453  Candidate  GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 before 2.3.2-r10 does not restrict the use of LD_DEBUG for a setuid program, which allows local users to gain sensitive information, such as the list of symbols used by the program.  Assigned (20050213)  None (candidate not yet proposed)    View
9882  CVE-2004-1454  Candidate  Cisco IOS 12.0S, 12.2, and 12.3, with Open Shortest Path First (OSPF) enabled, allows remote attackers to cause a denial of service (device reload) via a malformed OSPF packet.  Assigned (20050213)  None (candidate not yet proposed)    View
9883  CVE-2004-1455  Candidate  Stack-based buffer overflow in Xine-lib-rc5 in xine-lib 1_rc5-r2 and earlier allows remote attackers to execute arbitrary code via crafted playlists that result in a long vcd:// URL.  Assigned (20050213)  None (candidate not yet proposed)    View

Page 1151 of 20943, showing 5 records out of 104715 total, starting on record 5751, ending on 5755

Actions