CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7995  CVE-2003-1171  Candidate  Heap-based buffer overflow in the sec_filter_out function in mod_security 1.7RC1 through 1.7.1 in Apache 2 allows remote attackers to execute arbitrary code via a server side script that sends a large amount of data.  Assigned (20050504)  None (candidate not yet proposed)    View
7994  CVE-2003-1170  Candidate  Format string vulnerability in main.cpp in kpopup 0.9.1 and 0.9.5pre2 allows local users to cause a denial of service (segmentation fault) and possibly execute arbitrary code via format string specifiers in command line arguments.  Assigned (20050504)  None (candidate not yet proposed)    View
7993  CVE-2003-1169  Candidate  DATEV Nutzungskontrolle 2.1 and 2.2 has insecure write permissions for critical registry keys, which allows local users to bypass access restrictions by importing NukoInfo values in certain DATEV keys, which disables Nutzungskontrolle.  Assigned (20050504)  None (candidate not yet proposed)    View
7992  CVE-2003-1168  Candidate  HTTP Commander 4.0 allows remote attackers to obtain sensitive information via an HTTP request that contains a . (dot) in the file parameter, which reveals the installation path in an error message.  Assigned (20050504)  None (candidate not yet proposed)    View
7991  CVE-2003-1167  Candidate  misc.cpp in KPopup 0.9.1 trusts the PATH variable when executing killall, which allows local users to elevate their privileges by modifying the PATH variable to reference a malicious killall program.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 19345 of 20943, showing 5 records out of 104715 total, starting on record 96721, ending on 96725

Actions