CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6965  CVE-2003-0136  Candidate  psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/before file.  Assigned (20030313)  None (candidate not yet proposed)    View
6967  CVE-2003-0138  Candidate  Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.  Assigned (20030313)  NOOP(1) Christey  Christey> MANDRAKE:MDKSA-2003:043 | (as suggested by Vincent Danen of Mandrake)  View
6968  CVE-2003-0139  Candidate  Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and "ticket splicing."  Assigned (20030313)  NOOP(1) Christey  Christey> MANDRAKE:MDKSA-2003:043 | (as suggested by Vincent Danen of Mandrake)  View
6969  CVE-2003-0140  Candidate  Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder.  Assigned (20030313)  None (candidate not yet proposed)    View
6970  CVE-2003-0141  Candidate  The PNG deflate algorithm in RealOne Player 6.0.11.x and earlier, RealPlayer 8/RealPlayer Plus 8 6.0.9.584, and other versions allows remote attackers to corrupt the heap and overwrite arbitrary memory via a PNG graphic file format containing compressed data using fixed trees that contain the length values 286-287, which are treated as a very large length.  Assigned (20030313)  None (candidate not yet proposed)    View

Page 20303 of 20943, showing 5 records out of 104715 total, starting on record 101511, ending on 101515

Actions