CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8846  CVE-2004-0418  Candidate  serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data.  Assigned (20040416)  None (candidate not yet proposed)    View
8847  CVE-2004-0419  Candidate  XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0, which could allow remote attackers to connect to the port, in violation of the intended restrictions.  Assigned (20040416)  None (candidate not yet proposed)    View
8832  CVE-2004-0404  Candidate  logcheck before 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary directory in /var/tmp.  Assigned (20040414)  None (candidate not yet proposed)    View
8820  CVE-2004-0392  Candidate  racoon before 20040407b allows remote attackers to cause a denial of service (infinite loop and dropped connections) via an IKE message with a malformed Generic Payload Header containing invalid (1) "Security Association Next Payload" and (2) "RESERVED" fields.  Assigned (20040413)  None (candidate not yet proposed)    View
8821  CVE-2004-0393  Candidate  Format string vulnerability in the msg function for rlpr daemon (rlprd) 2.0.4 allows remote attackers to execute arbitrary code via format string specifiers in a buffer that can not be resolved, which is provided to the syslog function.  Assigned (20040413)  None (candidate not yet proposed)    View

Page 20091 of 20943, showing 5 records out of 104715 total, starting on record 100451, ending on 100455

Actions