CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6975  CVE-2003-0146  Candidate  Multiple vulnerabilities in NetPBM 9.20 and earlier, and possibly other versions, may allow remote attackers to cause a denial of service or execute arbitrary code via "maths overflow errors" such as (1) integer signedness errors or (2) integer overflows, which lead to buffer overflows.  Modified (20050311)  ACCEPT(3) Baker, Cole, Green | MODIFY(1) Cox | NOOP(2) Christey, Wall  Christey> MANDRAKE:MDKSA-2003:036 | URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:036 | CHANGE> [Cox changed vote from ACCEPT to MODIFY] | Cox> REDHAT:RHSA-2003:061 | Cox> ADDREF REDHAT:RHSA-2003:060 | Christey> MANDRAKE:MDKSA-2003:036 | (as suggested by Vincent Danen of Mandrake) | Christey> CONECTIVA:CLA-2003:656  View
6974  CVE-2003-0145  Entry  Unknown vulnerability in tcpdump before 3.7.2 related to an inability to "Handle unknown RADIUS attributes properly," allows remote attackers to cause a denial of service (infinite loop), a different vulnerability than CAN-2003-0093.        View
6973  CVE-2003-0144  Candidate  Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) user name.  Modified (20071113)  ACCEPT(4) Armstrong, Cole, Green, Jones | NOOP(2) Christey, Cox  Christey> DEBIAN:DSA-267 | URL:http://www.debian.org/security/2003/dsa-267 | Christey> DEBIAN:DSA-275 | URL:http://www.debian.org/security/2003/dsa-275 | Christey> DEBIAN:DSA-267 | URL:http://www.debian.org/security/2003/dsa-267 | Christey> SGI:20030406-02-P | Christey> MANDRAKE:MDKSA-2003:059 | URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:059  View
6972  CVE-2003-0143  Entry  The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authenticated users to execute arbitrary code via a buffer overflow in a mdef command with a long macro name.        View
6971  CVE-2003-0142  Candidate  Adobe Acrobat Reader (acroread) 6, under certain circumstances when running with the "Certified plug-ins only" option disabled, loads plug-ins with signatures used for older versions of Acrobat, which can allow attackers to cause Acrobat to enter Certified mode and run untrusted plugins by modifying the CTIsCertifiedMode function.  Assigned (20030313)  None (candidate not yet proposed)    View

Page 19549 of 20943, showing 5 records out of 104715 total, starting on record 97741, ending on 97745

Actions