CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8970 | CVE-2004-0542 | Candidate | PHP before 4.3.7 on Win32 platforms does not properly filter all shell metacharacters, which allows local or remote attackers to execute arbitrary code, overwrite files, and access internal environment variables via (1) the "%", "|", or ">" characters to the escapeshellcmd function, or (2) the "%" character to the escapeshellarg function. | Assigned (20040608) | None (candidate not yet proposed) | View | |
8969 | CVE-2004-0541 | Candidate | Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable). | Assigned (20040604) | None (candidate not yet proposed) | View | |
8968 | CVE-2004-0540 | Candidate | Microsoft Windows 2000, when running in a domain whose Fully Qualified Domain Name (FQDN) is exactly 8 characters long, does not prevent users with expired passwords from logging on to the domain. | Assigned (20040604) | None (candidate not yet proposed) | View | |
8967 | CVE-2004-0539 | Candidate | The "Show in Finder" button in the Safari web browser in Mac OS X 10.3.4 and 10.2.8 may execute downloaded applications, which could allow remote attackers to execute arbitrary code. | Assigned (20040604) | None (candidate not yet proposed) | View | |
8966 | CVE-2004-0538 | Candidate | LaunchServices in Mac OS X 10.3.4 and 10.2.8 automatically registers and executes new applications, which could allow attackers to execute arbitrary code without warning the user. | Assigned (20040604) | None (candidate not yet proposed) | View |
Page 19150 of 20943, showing 5 records out of 104715 total, starting on record 95746, ending on 95750