CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8467  CVE-2004-0039  Candidate  Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Check Point Firewall-1 HTTP Security Server included with NG FP1, FP2, and FP3 allows remote attackers to execute arbitrary code via HTTP requests that cause format string specifiers to be used in an error message, as demonstrated using the scheme of a URI.  Modified (20050818)  ACCEPT(4) Armstrong, Baker, Cole, Wall | NOOP(1) Cox    View
8736  CVE-2004-0308  Candidate  Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS15600 before 1.3(0) allows a superuser whose account is locked out, disabled, or suspended to gain unauthorized access via a Telnet connection to the VxWorks shell.  Modified (20040820)  ACCEPT(4) Armstrong, Baker, Cole, Wall | NOOP(1) Cox    View
8788  CVE-2004-0360  Candidate  Unknown vulnerability in passwd(1) in Solaris 8.0 and 9.0 allows local users to gain privileges via unknown attack vectors.  Proposed (20040318)  ACCEPT(4) Armstrong, Baker, Cole, Wall | NOOP(1) Cox    View
8686  CVE-2004-0258  Candidate  Multiple buffer overflows in RealOne Player, RealOne Player 2.0, RealOne Enterprise Desktop, and RealPlayer Enterprise allow remote attackers to execute arbitrary code via malformed (1) .RP, (2) .RT, (3) .RAM, (4) .RPM or (5) .SMIL files.  Proposed (20040318)  ACCEPT(4) Armstrong, Baker, Cole, Wall | NOOP(1) Cox    View
5089  CVE-2002-0699  Candidate  Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user"s system via HTML.  Modified (20061101)  ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(2) Foat, Frech | NOOP(2) Christey, Cox  Foat> Replace the word "Unknown" with "A" and change "allow" to "allows". | Christey> The "Unknown" portion of the vulnerability statement is used | to emphasize that the vendor has not provided sufficient | information to understand the cause or nature of the problem. | This is important because this vagueness makes it difficult | or impossible to resolve it with vulnerability reports | from other sources, increasing the risk of duplication. | | Most candidates affected by CD:VAGUE will use this description | style. | Christey> XF:win-certificate-enrollment-dos(9982) | URL:http://www.iss.net/security_center/static/9982.php | BID:5593 | URL:http://www.securityfocus.com/bid/5593 | Frech> XF:win-certificate-enrollment-dos(9982)  View

Page 19942 of 20943, showing 5 records out of 104715 total, starting on record 99706, ending on 99710

Actions