CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9268  CVE-2004-0840  Candidate  The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.  Assigned (20040908)  None (candidate not yet proposed)    View
9269  CVE-2004-0841  Candidate  Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."  Assigned (20040908)  None (candidate not yet proposed)    View
9270  CVE-2004-0842  Candidate  Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "<STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."  Assigned (20040908)  None (candidate not yet proposed)    View
9271  CVE-2004-0843  Candidate  Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."  Assigned (20040908)  None (candidate not yet proposed)    View
9272  CVE-2004-0844  Candidate  Internet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter displayed address bars and spoof web pages via a URL containing special characters, facilitating phishing attacks, aka the "Address Bar Spoofing on Double Byte Character Set Systems Vulnerability."  Assigned (20040908)  None (candidate not yet proposed)    View

Page 20001 of 20943, showing 5 records out of 104715 total, starting on record 100001, ending on 100005

Actions