CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
7865 | CVE-2003-1041 | Candidate | Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension. NOTE: this bug may overlap CVE-2004-0475. | Assigned (20040513) | None (candidate not yet proposed) | View | |
7864 | CVE-2003-1040 | Candidate | kmod in the Linux kernel does not set its uid, suid, gid, or sgid to 0, which allows local users to cause a denial of service (crash) by sending certain signals to kmod. | Assigned (20040317) | None (candidate not yet proposed) | View | |
7863 | CVE-2003-1039 | Candidate | Multiple buffer overflows in the mySAP.com architecture for SAP allow remote attackers to execute arbitrary code via a long HTTP Host header to (1) Message Server, (2) Web Dispatcher, or (3) Application Server. | Assigned (20040315) | None (candidate not yet proposed) | View | |
7862 | CVE-2003-1038 | Candidate | The AGate component for SAP Internet Transaction Server (ITS) allows remote attackers to obtain sensitive information via a ~command parameter with an AgateInstallCheck value, which provides a list of installed DLLs and full pathnames. | Assigned (20040315) | None (candidate not yet proposed) | View | |
7861 | CVE-2003-1037 | Candidate | Format string vulnerability in the WGate component for SAP Internet Transaction Server (ITS) allows remote attackers to execute arbitrary code via a high "trace level." | Assigned (20040315) | None (candidate not yet proposed) | View |
Page 19371 of 20943, showing 5 records out of 104715 total, starting on record 96851, ending on 96855