CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9804  CVE-2004-1376  Candidate  Directory traversal vulnerability in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote malicious FTP servers to overwrite arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.  Assigned (20050110)  None (candidate not yet proposed)    View
11249  CVE-2005-0043  Candidate  Buffer overflow in Apple iTunes 4.7 allows remote attackers to execute arbitrary code via a long URL in (1) .m3u or (2) .pls playlist files.  Assigned (20050110)  None (candidate not yet proposed)    View
9790  CVE-2004-1362  Candidate  The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO8859P1 character set, does not perform character conversions properly, which allows remote attackers to bypass access restrictions for certain procedures via an encoded URL with "%FF" encoded sequences that are improperly converted to "Y" characters.  Assigned (20050107)  None (candidate not yet proposed)    View
9791  CVE-2004-1363  Candidate  Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed.  Assigned (20050107)  None (candidate not yet proposed)    View
9792  CVE-2004-1364  Candidate  Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOMEin directory.  Assigned (20050107)  None (candidate not yet proposed)    View

Page 19885 of 20943, showing 5 records out of 104715 total, starting on record 99421, ending on 99425

Actions