CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9820  CVE-2004-1392  Candidate  PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.  Assigned (20050205)  None (candidate not yet proposed)    View
9819  CVE-2004-1391  Candidate  Untrusted execution path vulnerability in the PPPoE daemon (PPPoEd) in QNX RTP 6.1 allows local users to execute arbitrary programs by modifying the PATH environment variable to point to a malicious mount program.  Assigned (20050205)  None (candidate not yet proposed)    View
9818  CVE-2004-1390  Candidate  Multiple buffer overflows in the PPPoE daemon (PPPoEd) in QNX RTP 6.1 allow remote attackers to execute arbitrary code via a long argument to the (1) -F, (2) name, (3) en, (4) upscript, (5) downscript, (6) retries, (7) timeout, (8) scriptdetach, (9) noscript, (10) nodetach, (11) remote_mac, or (12) local_mac flags.  Assigned (20050205)  None (candidate not yet proposed)    View
9817  CVE-2004-1389  Candidate  Unknown vulnerability in the Veritas NetBackup Administrative Assistant interface for NetBackup BusinesServer 3.4, 3.4.1, and 4.5, DataCenter 3.4, 3.4.1, and 4.5, Enterprise Server 5.1, and NetBackup Server 5.0 and 5.1, allows attackers to execute arbitrary commands via the bpjava-susvc process, possibly related to the call-back feature.  Assigned (20050131)  None (candidate not yet proposed)    View
9816  CVE-2004-1388  Candidate  Format string vulnerability in the gpsd_report function for BerliOS GPD daemon (gpsd, formerly pygps) 1.9.0 through 2.7 allows remote attackers to execute arbitrary code via certain GPS requests containing format string specifiers that are not properly handled in syslog calls.  Assigned (20050131)  None (candidate not yet proposed)    View

Page 18980 of 20943, showing 5 records out of 104715 total, starting on record 94896, ending on 94900

Actions