CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
7253 | CVE-2003-0426 | Candidate | The installation of Apple QuickTime / Darwin Streaming Server before 4.1.3f starts the administration server with a "Setup Assistant" page that allows remote attackers to set the administrator password and gain privileges before the real administrator. | Assigned (20030611) | None (candidate not yet proposed) | View | |
4212 | CVE-2001-1409 | Candidate | dexconf in XFree86 Xserver 4.1.0-2 creates the /dev/dri directory with insecure permissions (666), which allows local users to replace or create files in the root file system. | Assigned (20030611) | None (candidate not yet proposed) | View | |
7329 | CVE-2003-0502 | Candidate | Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to cause a denial of service (crash) via a .. (dot dot) sequence followed by an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than CVE-2003-0421. | Assigned (20030611) | None (candidate not yet proposed) | View | |
7217 | CVE-2003-0390 | Candidate | Multiple buffer overflows in Options Parsing Tool (OPT) shared library 3.18 and earlier, when used in setuid programs, may allow local users to execute arbitrary code via long command line options that are fed into macros such as opt_warn_2, as used in functions such as opt_atoi. | Assigned (20030610) | None (candidate not yet proposed) | View | |
7218 | CVE-2003-0391 | Candidate | Format string vulnerability in Magic WinMail Server 2.3, and possibly other 2.x versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the PASS command. | Assigned (20030610) | None (candidate not yet proposed) | View |
Page 20246 of 20943, showing 5 records out of 104715 total, starting on record 101226, ending on 101230