CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9215 | CVE-2004-0787 | Candidate | Cross-site scripting (XSS) vulnerability in the web frontend in OpenCA 0.9.1-8 and earlier, and 0.9.2 RC6 and earlier, allows remote attackers to inject arbitrary web script or HTML via the form input fields. | Assigned (20040817) | None (candidate not yet proposed) | View | |
9214 | CVE-2004-0786 | Candidate | The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool. | Assigned (20040817) | None (candidate not yet proposed) | View | |
9213 | CVE-2004-0785 | Candidate | Multiple buffer overflows in Gaim before 0.82 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) Rich Text Format (RTF) messages, (2) a long hostname for the local system as obtained from DNS, or (3) a long URL that is not properly handled by the URL decoder. | Assigned (20040817) | None (candidate not yet proposed) | View | |
9212 | CVE-2004-0784 | Candidate | The smiley theme functionality in Gaim before 0.82 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of the tar file that is dragged to the smiley selector. | Assigned (20040817) | None (candidate not yet proposed) | View | |
9211 | CVE-2004-0783 | Candidate | Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0688). | Assigned (20040817) | None (candidate not yet proposed) | View |
Page 19101 of 20943, showing 5 records out of 104715 total, starting on record 95501, ending on 95505