CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9130 | CVE-2004-0702 | Candidate | DBI in Bugzilla 2.17.1 through 2.17.7 displays the database password in an error message when the SQL server is not running, which could allow remote attackers to gain sensitive information. | Assigned (20040720) | None (candidate not yet proposed) | View | |
9129 | CVE-2004-0701 | Candidate | Sun Ray Server Software (SRSS) 1.3 and 2.0 for Solaris 2.6, 7 and 8 does not properly detect a smartcard removal when the card is quickly removed, reinserted, and removed again, which could cause a user session to stay logged in and allow local users to gain unauthorized access. | Assigned (20040720) | None (candidate not yet proposed) | View | |
9128 | CVE-2004-0700 | Candidate | Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HTTPS that are handled by the ssl_log function. | Assigned (20040719) | None (candidate not yet proposed) | View | |
9127 | CVE-2004-0699 | Candidate | Heap-based buffer overflow in ASN.1 decoding library in Check Point VPN-1 products, when Aggressive Mode IKE is implemented, allows remote attackers to execute arbitrary code by initiating an IKE negotiation and then sending an IKE packet with malformed ASN.1 data. | Assigned (20040715) | None (candidate not yet proposed) | View | |
9126 | CVE-2004-0698 | Candidate | 4D WebSTAR 5.3.2 and earlier allows local users to read and modify arbitrary files via a symlink attack. | Assigned (20040714) | None (candidate not yet proposed) | View |
Page 19118 of 20943, showing 5 records out of 104715 total, starting on record 95586, ending on 95590