CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8060 | CVE-2003-1236 | Candidate | Multiple format string vulnerabilities in the logger function in netzio.c for Tanne 0.6.17 allows remote attackers to execute arbitrary code via format string specifiers in syslog. | Assigned (20051116) | None (candidate not yet proposed) | View | |
8059 | CVE-2003-1235 | Candidate | BRW WebWeaver 1.03 allows remote attackers to obtain sensitive server environment information via a URL request for testcgi.exe, which lists the values of environment variables and the current working directory. | Assigned (20051116) | None (candidate not yet proposed) | View | |
8058 | CVE-2003-1234 | Candidate | Integer overflow in the f_count counter in FreeBSD before 4.2 through 5.0 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via multiple calls to (1) fpathconf and (2) lseek, which do not properly decrement f_count through a call to fdrop. | Assigned (20051116) | None (candidate not yet proposed) | View | |
8057 | CVE-2003-1233 | Candidate | Pedestal Software Integrity Protection Driver (IPD) 1.3 and earlier allows privileged attackers, such as rootkits, to bypass file access restrictions to the Windows kernel by using the NtCreateSymbolicLinkObject function to create a symbolic link to (1) DevicePhysicalMemory or (2) to a drive letter using the subst command. | Assigned (20051028) | None (candidate not yet proposed) | View | |
8056 | CVE-2003-1232 | Candidate | Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, which allows user-assisted attackers to execute arbitrary commands, as demonstrated using the mode-name variable. | Assigned (20050926) | None (candidate not yet proposed) | View |
Page 19332 of 20943, showing 5 records out of 104715 total, starting on record 96656, ending on 96660