CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11914  CVE-2005-0708  Candidate  The sendfile system call in FreeBSD 4.8 through 4.11 and 5 through 5.4 can transfer portions of kernel memory if a file is truncated while it is being sent, which could allow remote attackers to obtain sensitive information.  Assigned (20050311)  None (candidate not yet proposed)    View
11915  CVE-2005-0709  Candidate  MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access libc calls, as demonstrated by using strcat, on_exit, and exit.  Assigned (20050311)  None (candidate not yet proposed)    View
11916  CVE-2005-0710  Candidate  MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to bypass library path restrictions and execute arbitrary libraries by using INSERT INTO to modify the mysql.func table, which is processed by the udf_init function.  Assigned (20050311)  None (candidate not yet proposed)    View
11917  CVE-2005-0711  Candidate  MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allows local users with CREATE TEMPORARY TABLE privileges to overwrite arbitrary files via a symlink attack.  Assigned (20050311)  None (candidate not yet proposed)    View
11918  CVE-2005-0712  Candidate  Mac OS X before 10.3.8 users world-writable permissions for certain directories, which may allow local users to gain privileges, possibly via the receipt cache or ColorSync profiles.  Assigned (20050311)  None (candidate not yet proposed)    View

Page 1285 of 20943, showing 5 records out of 104715 total, starting on record 6421, ending on 6425

Actions