CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8475  CVE-2004-0047  Candidate  Multiple programs in trr19 1.0 do not properly drop privileges before executing a system command, which could allow local users to gain privileges.  Modified (20071113)  ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall    View
8474  CVE-2004-0046  Candidate  Cross-site scripting (XSS) vulnerability in SnapStream PVS LITE allows remote attackers to inject arbitrary web script or HTML via a GET request containing a terminating """ (double quote) character.  Modified (20050430)  ACCEPT(2) Armstrong, Baker | NOOP(4) Cole, Cox, Wall, Williams  Williams> insufficient data.  View
8473  CVE-2004-0045  Entry  Buffer overflow in the ARTpost function in art.c in the control message handling code for INN 2.4.0 may allow remote attackers to execute arbitrary code.        View
8472  CVE-2004-0044  Entry  Cisco Personal Assistant 1.4(1) and 1.4(2) disables password authentication when "Allow Only Cisco CallManager Users" is enabled and the Corporate Directory settings refer to the directory service being used by Cisco CallManager, which allows remote attackers to gain access with a valid username.        View
8471  CVE-2004-0043  Candidate  Buffer overflow in Yahoo Instant Messenger 5.6.0.1351 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in the download feature.  Modified (20071113)  ACCEPT(3) Armstrong, Baker, Williams | NOOP(2) Cole, Cox | REVIEWING(1) Wall  Williams> http://lists.netsys.com/pipermail/full-disclosure/2004-January/015355.html | http://www.packetstormsecurity.nl/0401-advisories/yahooIM.txt  View

Page 19249 of 20943, showing 5 records out of 104715 total, starting on record 96241, ending on 96245

Actions