CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9406 | CVE-2004-0978 | Candidate | Heap-based buffer overflow in the Hrtbeat.ocx (Heartbeat) ActiveX control for Internet Explorer 5.01 through 6, when users who visit online gaming sites that are associated with MSN, allows remote attackers to execute arbitrary code via the SetupData parameter. | Assigned (20041020) | None (candidate not yet proposed) | View | |
9407 | CVE-2004-0979 | Candidate | Internet Explorer on Windows XP does not properly modify the "Drag and Drop or copy and paste files" setting when the user sets it to "Disable" or "Prompt," which may enable security-sensitive operations that are inconsistent with the user"s intended configuration. | Assigned (20041020) | None (candidate not yet proposed) | View | |
9393 | CVE-2004-0965 | Candidate | stmkfont in HP-UX B.11.00 through B.11.23 relies on the user-specified PATH when executing certain commands, which allows local users to execute arbitrary code by modifying the PATH environment variable to point to malicious programs. | Assigned (20041019) | None (candidate not yet proposed) | View | |
9394 | CVE-2004-0966 | Candidate | The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as used in Trustix Secure Linux 1.5 through 2.1 and other operating systems, allows local users to overwrite files via a symlink attack on temporary files. | Assigned (20041019) | None (candidate not yet proposed) | View | |
9395 | CVE-2004-0967 | Candidate | The (1) pj-gs.sh, (2) ps2epsi, (3) pv.sh, and (4) sysvlp.sh scripts in the ESP Ghostscript (espgs) package in Trustix Secure Linux 1.5 through 2.1, and other operating systems, allow local users to overwrite files via a symlink attack on temporary files. | Assigned (20041019) | None (candidate not yet proposed) | View |
Page 19973 of 20943, showing 5 records out of 104715 total, starting on record 99861, ending on 99865