CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8970  CVE-2004-0542  Candidate  PHP before 4.3.7 on Win32 platforms does not properly filter all shell metacharacters, which allows local or remote attackers to execute arbitrary code, overwrite files, and access internal environment variables via (1) the "%", "|", or ">" characters to the escapeshellcmd function, or (2) the "%" character to the escapeshellarg function.  Assigned (20040608)  None (candidate not yet proposed)    View
8969  CVE-2004-0541  Candidate  Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable).  Assigned (20040604)  None (candidate not yet proposed)    View
8968  CVE-2004-0540  Candidate  Microsoft Windows 2000, when running in a domain whose Fully Qualified Domain Name (FQDN) is exactly 8 characters long, does not prevent users with expired passwords from logging on to the domain.  Assigned (20040604)  None (candidate not yet proposed)    View
8967  CVE-2004-0539  Candidate  The "Show in Finder" button in the Safari web browser in Mac OS X 10.3.4 and 10.2.8 may execute downloaded applications, which could allow remote attackers to execute arbitrary code.  Assigned (20040604)  None (candidate not yet proposed)    View
8966  CVE-2004-0538  Candidate  LaunchServices in Mac OS X 10.3.4 and 10.2.8 automatically registers and executes new applications, which could allow attackers to execute arbitrary code without warning the user.  Assigned (20040604)  None (candidate not yet proposed)    View

Page 19150 of 20943, showing 5 records out of 104715 total, starting on record 95746, ending on 95750

Actions