CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11019  CVE-2004-2593  Candidate  Buffer overflow in command-packet processing of Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a packet with a long cmd_args buffer.  Assigned (20051129)  None (candidate not yet proposed)    View
11020  CVE-2004-2594  Candidate  Absolute path traversal vulnerability in Quake II server before R1Q2 on Windows, as used in multiple products, allows remote attackers to read arbitrary files via a "/" in a pathname argument, as demonstrated by "download /server.cfg".  Assigned (20051129)  None (candidate not yet proposed)    View
11021  CVE-2004-2595  Candidate  Absolute path traversal vulnerability in Quake II server before R1Q2 on Linux, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a download command with a full pathname for a directory in the argument, which causes the server to crash when it cannot read data.  Assigned (20051129)  None (candidate not yet proposed)    View
11022  CVE-2004-2596  Candidate  Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection slots) via a large number of connections from the same IP address.  Assigned (20051129)  None (candidate not yet proposed)    View
11023  CVE-2004-2597  Candidate  Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based access control rules via a userinfo string that already contains an "ip" key/value pair but is also long enough to cause a new key/value pair to be truncated, which interferes with the server"s ability to find the client"s IP address.  Assigned (20051129)  None (candidate not yet proposed)    View

Page 18653 of 20943, showing 5 records out of 104715 total, starting on record 93261, ending on 93265

Actions