CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8641  CVE-2004-0213  Candidate  Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and bypassing the GUI, then sending another message to winhlp32 in order to open a user-selected file, a different vulnerability than CVE-2003-0908.  Assigned (20040311)  None (candidate not yet proposed)    View
8642  CVE-2004-0214  Candidate  Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.  Assigned (20040311)  None (candidate not yet proposed)    View
8643  CVE-2004-0215  Candidate  Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.  Assigned (20040311)  None (candidate not yet proposed)    View
8644  CVE-2004-0216  Candidate  Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.  Assigned (20040311)  None (candidate not yet proposed)    View
8623  CVE-2004-0195  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20040309)  None (candidate not yet proposed)    View

Page 20109 of 20943, showing 5 records out of 104715 total, starting on record 100541, ending on 100545

Actions