CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9406  CVE-2004-0978  Candidate  Heap-based buffer overflow in the Hrtbeat.ocx (Heartbeat) ActiveX control for Internet Explorer 5.01 through 6, when users who visit online gaming sites that are associated with MSN, allows remote attackers to execute arbitrary code via the SetupData parameter.  Assigned (20041020)  None (candidate not yet proposed)    View
9407  CVE-2004-0979  Candidate  Internet Explorer on Windows XP does not properly modify the "Drag and Drop or copy and paste files" setting when the user sets it to "Disable" or "Prompt," which may enable security-sensitive operations that are inconsistent with the user"s intended configuration.  Assigned (20041020)  None (candidate not yet proposed)    View
9393  CVE-2004-0965  Candidate  stmkfont in HP-UX B.11.00 through B.11.23 relies on the user-specified PATH when executing certain commands, which allows local users to execute arbitrary code by modifying the PATH environment variable to point to malicious programs.  Assigned (20041019)  None (candidate not yet proposed)    View
9394  CVE-2004-0966  Candidate  The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as used in Trustix Secure Linux 1.5 through 2.1 and other operating systems, allows local users to overwrite files via a symlink attack on temporary files.  Assigned (20041019)  None (candidate not yet proposed)    View
9395  CVE-2004-0967  Candidate  The (1) pj-gs.sh, (2) ps2epsi, (3) pv.sh, and (4) sysvlp.sh scripts in the ESP Ghostscript (espgs) package in Trustix Secure Linux 1.5 through 2.1, and other operating systems, allow local users to overwrite files via a symlink attack on temporary files.  Assigned (20041019)  None (candidate not yet proposed)    View

Page 19973 of 20943, showing 5 records out of 104715 total, starting on record 99861, ending on 99865

Actions