CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7345  CVE-2003-0518  Candidate  The screen saver in MacOS X allows users with physical access to cause the screen saver to crash and gain access to the underlying session via a large number of characters in the password field, possibly triggering a buffer overflow.  Assigned (20030707)  None (candidate not yet proposed)    View
7344  CVE-2003-0517  Candidate  faxrunqd.in in mgetty 1.1.28 and earlier allows local users to overwrite files via a symlink attack on JOB files.  Assigned (20030707)  None (candidate not yet proposed)    View
7343  CVE-2003-0516  Candidate  cnd.c in mgetty 1.1.28 and earlier does not properly filter non-printable characters and quotes, which may allow remote attackers to execute arbitrary commands via shell metacharacters in (1) caller ID or (2) caller name strings.  Assigned (20030707)  None (candidate not yet proposed)    View
7342  CVE-2003-0515  Candidate  SQL injection vulnerabilities in the (1) PostgreSQL or (2) MySQL authentication modules for teapop 0.3.5 and earlier allow attackers to execute arbitrary SQL and possibly gain privileges.  Assigned (20030707)  None (candidate not yet proposed)    View
7341  CVE-2003-0514  Candidate  Apple Safari allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Safari to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.  Proposed (20040318)  ACCEPT(4) Armstrong, Baker, Balinsky, Cole | MODIFY(1) Frech | NOOP(2) Cox, Wall | REVIEWING(1) Christey  Frech> XF:web-browser-cookie-bypass(15424) | http://xforce.iss.net/xforce/xfdb/15424 | Christey> Consider whether this is really a design-level problem that applies to | the interaction between any vulnerable XSS, its associated domain, and | any web browser, because browsers enforce security boundaries at the | domain level. If so, then the "%2e%2e" problem may be a red herring, | or a single attack vector of any number of vectors. | | CVE-2003-0513, CVE-2003-0514, CVE-2003-0592, CVE-2003-0593, | and CVE-2003-0594 all cover this specific issue (each for a | different browser).  View

Page 19475 of 20943, showing 5 records out of 104715 total, starting on record 97371, ending on 97375

Actions