CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9070  CVE-2004-0642  Candidate  Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary code.  Assigned (20040708)  None (candidate not yet proposed)    View
9069  CVE-2004-0641  Candidate  Thomson SpeedTouch 510 ADSL Router with firmware GV8BAA3.270, and possibly earlier versions, generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.  Assigned (20040708)  None (candidate not yet proposed)    View
9068  CVE-2004-0640  Candidate  Format string vulnerability in the SSL_set_verify function in telnetd.c for SSLtelnet daemon (SSLtelnetd) 0.13 allows remote attackers to execute arbitrary code.  Assigned (20040708)  None (candidate not yet proposed)    View
9067  CVE-2004-0639  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or script via (1) the $mailer variable in read_body.php, (2) the $senderNames_part variable in mailbox_display.php, and possibly other vectors including (3) the $event_title variable or (4) the $event_text variable.  Assigned (20040708)  None (candidate not yet proposed)    View
9066  CVE-2004-0638  Candidate  Buffer overflow in the KSDWRTB function in the dbms_system package (dbms_system.ksdwrt) for Oracle 9i Database Server Release 2 9.2.0.3 and 9.2.0.4, 9i Release 1 9.0.1.4 and 9.0.1.5, and 8i Release 1 8.1.7.4, allows remote authorized users to execute arbitrary code via a long second argument.  Assigned (20040707)  None (candidate not yet proposed)    View

Page 19130 of 20943, showing 5 records out of 104715 total, starting on record 95646, ending on 95650

Actions