CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8645 | CVE-2004-0217 | Candidate | The LiveUpdate capability (liveupdate.sh) in Symantec AntiVirus Scan Engine 4.0 and 4.3 for Red Hat Linux allows local users to create or append to arbitrary files via a symlink attack on /tmp/LiveUpdate.log. | Proposed (20040318) | ACCEPT(2) Armstrong, Cole | MODIFY(1) Frech | NOOP(1) Cox | REVIEWING(1) Wall | Frech> XF:symantec-scanengine-race-condition(15215) | http://xforce.iss.net/xforce/xfdb/15215 | View |
8644 | CVE-2004-0216 | Candidate | Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow. | Assigned (20040311) | None (candidate not yet proposed) | View | |
8643 | CVE-2004-0215 | Candidate | Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header. | Assigned (20040311) | None (candidate not yet proposed) | View | |
8642 | CVE-2004-0214 | Candidate | Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba. | Assigned (20040311) | None (candidate not yet proposed) | View | |
8641 | CVE-2004-0213 | Candidate | Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and bypassing the GUI, then sending another message to winhlp32 in order to open a user-selected file, a different vulnerability than CVE-2003-0908. | Assigned (20040311) | None (candidate not yet proposed) | View |
Page 19215 of 20943, showing 5 records out of 104715 total, starting on record 96071, ending on 96075