CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8540  CVE-2004-0112  Candidate  The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.  Assigned (20040202)  None (candidate not yet proposed)    View
8539  CVE-2004-0111  Entry  gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.        View
8538  CVE-2004-0110  Candidate  Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.  Modified (20100819)  ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | NOOP(1) Christey  Christey> CONECTIVA:CLA-2004:836 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000836 | Christey> Add APPLE-SA-2004-04-05 | CONFIRM:http://lists.apple.com/mhonarc/security-announce/msg00047.html | Green> VERIFIED-BY-SOMEONE-I-TRUST | Christey> Normalize Trustix references | Christey> FEDORA:FEDORA-2004-1324 | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109035140702164&w=2  View
8537  CVE-2004-0109  Candidate  Buffer overflow in the ISO9660 file system component for Linux kernel 2.4.x, 2.5.x and 2.6.x, allows local users with physical access to overflow kernel memory and execute arbitrary code via a malformed CD containing a long symbolic link entry.  Assigned (20040202)  None (candidate not yet proposed)    View
8536  CVE-2004-0108  Entry  The isag utility, which processes sysstat data, allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CAN-2004-0107.        View

Page 19236 of 20943, showing 5 records out of 104715 total, starting on record 96176, ending on 96180

Actions