CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11035 | CVE-2004-2609 | Candidate | The stuffit.com executable on Symantec PowerQuest DeployCenter 5.5 boot disks allows local users to obtain sensitive information (an unencrypted password for a Windows domain account) via four "stuffit /f:stuffit.dat" invocations, possibly due to a buffer overflow. | Assigned (20051204) | None (candidate not yet proposed) | View | |
11034 | CVE-2004-2608 | Candidate | SmartWebby Smart Guest Book stores SmartGuestBook.mdb (aka the "news database") under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the unencrypted username and password of the administrator"s account. | Assigned (20051204) | None (candidate not yet proposed) | View | |
11033 | CVE-2004-2607 | Candidate | A numeric casting discrepancy in sdla_xfer in Linux kernel 2.6.x up to 2.6.5 and 2.4 up to 2.4.29-rc1 allows local users to read portions of kernel memory via a large len argument, which is received as an int but cast to a short, which prevents a read loop from filling a buffer. | Assigned (20051202) | None (candidate not yet proposed) | View | |
11032 | CVE-2004-2606 | Candidate | The Web interface in Linksys WRT54G 2.02.7 and BEFSR41 version 3, with the firewall disabled, allows remote attackers to attempt to login to an administration web page, even when the configuration specifies that remote administration is disabled. | Assigned (20051129) | None (candidate not yet proposed) | View | |
11031 | CVE-2004-2605 | Candidate | aStats 1.6.5 allows local users to overwrite arbitrary files via a symlink attack on (1) the aStats-Graphic-Signature-Generation file and (2) certain PNG image files. | Assigned (20051129) | None (candidate not yet proposed) | View |
Page 18737 of 20943, showing 5 records out of 104715 total, starting on record 93681, ending on 93685