CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8060  CVE-2003-1236  Candidate  Multiple format string vulnerabilities in the logger function in netzio.c for Tanne 0.6.17 allows remote attackers to execute arbitrary code via format string specifiers in syslog.  Assigned (20051116)  None (candidate not yet proposed)    View
8059  CVE-2003-1235  Candidate  BRW WebWeaver 1.03 allows remote attackers to obtain sensitive server environment information via a URL request for testcgi.exe, which lists the values of environment variables and the current working directory.  Assigned (20051116)  None (candidate not yet proposed)    View
8058  CVE-2003-1234  Candidate  Integer overflow in the f_count counter in FreeBSD before 4.2 through 5.0 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via multiple calls to (1) fpathconf and (2) lseek, which do not properly decrement f_count through a call to fdrop.  Assigned (20051116)  None (candidate not yet proposed)    View
8057  CVE-2003-1233  Candidate  Pedestal Software Integrity Protection Driver (IPD) 1.3 and earlier allows privileged attackers, such as rootkits, to bypass file access restrictions to the Windows kernel by using the NtCreateSymbolicLinkObject function to create a symbolic link to (1) DevicePhysicalMemory or (2) to a drive letter using the subst command.  Assigned (20051028)  None (candidate not yet proposed)    View
8056  CVE-2003-1232  Candidate  Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, which allows user-assisted attackers to execute arbitrary commands, as demonstrated using the mode-name variable.  Assigned (20050926)  None (candidate not yet proposed)    View

Page 19332 of 20943, showing 5 records out of 104715 total, starting on record 96656, ending on 96660

Actions