CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7253  CVE-2003-0426  Candidate  The installation of Apple QuickTime / Darwin Streaming Server before 4.1.3f starts the administration server with a "Setup Assistant" page that allows remote attackers to set the administrator password and gain privileges before the real administrator.  Assigned (20030611)  None (candidate not yet proposed)    View
4212  CVE-2001-1409  Candidate  dexconf in XFree86 Xserver 4.1.0-2 creates the /dev/dri directory with insecure permissions (666), which allows local users to replace or create files in the root file system.  Assigned (20030611)  None (candidate not yet proposed)    View
7329  CVE-2003-0502  Candidate  Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to cause a denial of service (crash) via a .. (dot dot) sequence followed by an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than CVE-2003-0421.  Assigned (20030611)  None (candidate not yet proposed)    View
7217  CVE-2003-0390  Candidate  Multiple buffer overflows in Options Parsing Tool (OPT) shared library 3.18 and earlier, when used in setuid programs, may allow local users to execute arbitrary code via long command line options that are fed into macros such as opt_warn_2, as used in functions such as opt_atoi.  Assigned (20030610)  None (candidate not yet proposed)    View
7218  CVE-2003-0391  Candidate  Format string vulnerability in Magic WinMail Server 2.3, and possibly other 2.x versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the PASS command.  Assigned (20030610)  None (candidate not yet proposed)    View

Page 20246 of 20943, showing 5 records out of 104715 total, starting on record 101226, ending on 101230

Actions