CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8846 | CVE-2004-0418 | Candidate | serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data. | Assigned (20040416) | None (candidate not yet proposed) | View | |
8847 | CVE-2004-0419 | Candidate | XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0, which could allow remote attackers to connect to the port, in violation of the intended restrictions. | Assigned (20040416) | None (candidate not yet proposed) | View | |
8832 | CVE-2004-0404 | Candidate | logcheck before 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary directory in /var/tmp. | Assigned (20040414) | None (candidate not yet proposed) | View | |
8820 | CVE-2004-0392 | Candidate | racoon before 20040407b allows remote attackers to cause a denial of service (infinite loop and dropped connections) via an IKE message with a malformed Generic Payload Header containing invalid (1) "Security Association Next Payload" and (2) "RESERVED" fields. | Assigned (20040413) | None (candidate not yet proposed) | View | |
8821 | CVE-2004-0393 | Candidate | Format string vulnerability in the msg function for rlpr daemon (rlprd) 2.0.4 allows remote attackers to execute arbitrary code via format string specifiers in a buffer that can not be resolved, which is provided to the syslog function. | Assigned (20040413) | None (candidate not yet proposed) | View |
Page 20091 of 20943, showing 5 records out of 104715 total, starting on record 100451, ending on 100455