CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11228  CVE-2005-0022  Candidate  Buffer overflow in the spa_base64_to_bits function in Exim before 4.43, as originally obtained from Samba code, and as called by the auth_spa_client function, may allow attackers to execute arbitrary code during SPA authentication.  Assigned (20050104)  None (candidate not yet proposed)    View
9746  CVE-2004-1318  Candidate  Cross-site scripting (XSS) vulnerability in namazu.cgi for Namazu 2.0.13 and earlier allows remote attackers to inject arbitrary HTML and web script via a query that starts with a tab ("%09") character, which prevents the rest of the query from being properly sanitized.  Assigned (20050103)  None (candidate not yet proposed)    View
11207  CVE-2005-0001  Candidate  Race condition in the page fault handler (fault.c) for Linux kernel 2.2.x to 2.2.7, 2.4 to 2.4.29, and 2.6 to 2.6.10, when running on multiprocessor machines, allows local users to execute arbitrary code via concurrent threads that share the same virtual memory space and simultaneously request stack expansion.  Assigned (20050103)  None (candidate not yet proposed)    View
11208  CVE-2005-0002  Candidate  poppassd_pam 1.0 and earlier, when changing a user password, does not verify that the user entered the old password correctly, which allows remote attackers to change passwords for arbitrary users.  Assigned (20050103)  None (candidate not yet proposed)    View
11209  CVE-2005-0003  Candidate  The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a denial of service (system crash) or execute arbitrary code via a crafted ELF or a.out file.  Assigned (20050103)  None (candidate not yet proposed)    View

Page 19903 of 20943, showing 5 records out of 104715 total, starting on record 99511, ending on 99515

Actions