CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9585 | CVE-2004-1157 | Candidate | Opera 7.x up to 7.54, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability. | Assigned (20041208) | None (candidate not yet proposed) | View | |
9584 | CVE-2004-1156 | Candidate | Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability. | Assigned (20041208) | None (candidate not yet proposed) | View | |
9583 | CVE-2004-1155 | Candidate | Internet Explorer 5.01 through 6 allows remote attackers to spoof arbitrary web sites by injecting content from one window into another window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability. NOTE: later research shows that Internet Explorer 7 on Windows XP SP2 is also vulnerable. | Assigned (20041208) | None (candidate not yet proposed) | View | |
9582 | CVE-2004-1154 | Candidate | Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow. | Assigned (20041207) | None (candidate not yet proposed) | View | |
9581 | CVE-2004-1153 | Candidate | Format string vulnerability in Adobe Acrobat Reader 6.0.0 through 6.0.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an .ETD document containing format string specifiers in (1) title or (2) baseurl fields. | Assigned (20041207) | None (candidate not yet proposed) | View |
Page 19027 of 20943, showing 5 records out of 104715 total, starting on record 95131, ending on 95135