CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7032  CVE-2003-0204  Candidate  KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF files, related to missing -dPARANOIDSAFER and -dSAFER arguments when using the kghostview Ghostscript viewer.  Assigned (20030414)  NOOP(1) Christey  Christey> MANDRAKE:MDKSA-2003:049 | (as suggested by Vincent Danen of Mandrake)  View
6912  CVE-2003-0083  Candidate  Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.  Assigned (20030210)  NOOP(1) Christey  Christey> MANDRAKE:MDKSA-2003:050 | (as suggested by Vincent Danen of Mandrake)  View
6961  CVE-2003-0132  Candidate  A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.  Assigned (20030313)  NOOP(1) Christey  Christey> MANDRAKE:MDKSA-2003:050 | (as suggested by Vincent Danen of Mandrake)  View
2487  CVE-2000-0918  Candidate  Format string vulnerability in kvt in KDE 1.1.2 may allow local users to execute arbitrary commands via a DISPLAY environmental variable that contains formatting characters.  Proposed (20001129)  ACCEPT(2) Baker, Mell | NOOP(2) Cole, Wall | REVIEWING(1) Christey  Christey> May be a duplicate of CVE-2000-0373, but the ref"s in that CVE | are vague. I suspect this *isn"t* a duplicate because this is | a format string problem. | Baker> I think it is sufficiently different from 2000-0373.  View
8712  CVE-2004-0284  Candidate  Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(3) Armstrong, Christey, Cox | REVIEWING(1) Wall  Christey> MISC:http://www.acrossecurity.com/aspr/ASPR-2004-01-20-1-PUB.txt  View

Page 20645 of 20943, showing 5 records out of 104715 total, starting on record 103221, ending on 103225

Actions