CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8769  CVE-2004-0341  Candidate  WFTPD Pro Server 3.21 Release 1 allocates memory for a command until a 0Ah byte (newline) is sent, which allows local users to cause a denial of service (CPU consumption) by continuing to send a long command that does not contain a newline.  Modified (20050719)  ACCEPT(2) Armstrong, Wall | NOOP(2) Cole, Cox    View
8787  CVE-2004-0359  Candidate  Cross-site scripting (XSS) vulnerability in index.php for Invision Power Board 1.3 final allows remote attackers to execute arbitrary script as other users via the (1) c, (2) f, (3) showtopic, (4) showuser, or (5) username parameters.  Modified (20050719)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8652  CVE-2004-0224  Candidate  Multiple buffer overflows in (1) iso2022jp.c or (2) shiftjis.c for Courier-IMAP before 3.0.0, Courier before 0.45, and SqWebMail before 4.0.0 may allow remote attackers to execute arbitrary code "when Unicode character is out of BMP range."  Modified (20050719)  ACCEPT(4) Armstrong, Baker, Cole, Cox | MODIFY(1) Frech | NOOP(3) Christey, Green, Wall  Frech> XF:courier-codeset-converter-bo(15434) | http://xforce.iss.net/xforce/xfdb/15434 | Christey> BUGTRAQ:20040329 [ GLSA 200403-06 ] Multiple remote buffer overflow vulnerabilities in Courier | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108058112903373&w=2 | Christey> BUGTRAQ:20040329 [ GLSA 200403-06 ] Multiple remote buffer overflow vulnerabilities in Courier | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108058112903373&w=2 | Christey> MISC:http://www.debian.org/security/nonvulns-woody#CVE-2004-0075 | CHANGE> [Cox changed vote from REVIEWING to ACCEPT]  View
8761  CVE-2004-0333  Candidate  Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME archive with certain long MIME parameters.  Modified (20050808)  ACCEPT(4) Armstrong, Baker, Cole, Wall | NOOP(2) Christey, Cox  Christey> Consider this Gentoo reference: | BUGTRAQ:20040328 [ GLSA 200403-05 ] UUDeview MIME Buffer Overflow | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108057738810928&w=2 | | May need to rephrase this description to emphasize UUDeview | over WinZip.  View
8531  CVE-2004-0103  Candidate  crawl before 4.0.0 beta23 does not properly "apply a size check" when copying a certain environment variable, which may allow local users to gain privileges, possibly as a result of a buffer overflow.  Modified (20050808)  ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall    View

Page 20448 of 20943, showing 5 records out of 104715 total, starting on record 102236, ending on 102240

Actions