CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7355  CVE-2003-0528  Candidate  Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0715.  Assigned (20030708)  None (candidate not yet proposed)    View
7354  CVE-2003-0527  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20030708)  None (candidate not yet proposed)    View
7353  CVE-2003-0526  Candidate  Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in the default error pages (1) 500.htm for "500 Internal Server error" or (2) 404.htm for "404 Not Found."  Assigned (20030708)  None (candidate not yet proposed)    View
7352  CVE-2003-0525  Candidate  The getCanonicalPath function in Windows NT 4.0 may free memory that it does not own and cause heap corruption, which allows attackers to cause a denial of service (crash) via requests that cause a long file name to be passed to getCanonicalPath, as demonstrated on the IBM JVM using a long string to the java.io.getCanonicalPath Java method.  Assigned (20030708)  None (candidate not yet proposed)    View
7351  CVE-2003-0524  Candidate  Qt in Knoppix 3.1 Live CD allows local users to overwrite arbitrary files via a symlink attack on the qt_plugins_3.0rc temporary file in the .qt directory.  Assigned (20030708)  None (candidate not yet proposed)    View

Page 19473 of 20943, showing 5 records out of 104715 total, starting on record 97361, ending on 97365

Actions