CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8712  CVE-2004-0284  Candidate  Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(3) Armstrong, Christey, Cox | REVIEWING(1) Wall  Christey> MISC:http://www.acrossecurity.com/aspr/ASPR-2004-01-20-1-PUB.txt  View
2487  CVE-2000-0918  Candidate  Format string vulnerability in kvt in KDE 1.1.2 may allow local users to execute arbitrary commands via a DISPLAY environmental variable that contains formatting characters.  Proposed (20001129)  ACCEPT(2) Baker, Mell | NOOP(2) Cole, Wall | REVIEWING(1) Christey  Christey> May be a duplicate of CVE-2000-0373, but the ref"s in that CVE | are vague. I suspect this *isn"t* a duplicate because this is | a format string problem. | Baker> I think it is sufficiently different from 2000-0373.  View
6912  CVE-2003-0083  Candidate  Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.  Assigned (20030210)  NOOP(1) Christey  Christey> MANDRAKE:MDKSA-2003:050 | (as suggested by Vincent Danen of Mandrake)  View
6961  CVE-2003-0132  Candidate  A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.  Assigned (20030313)  NOOP(1) Christey  Christey> MANDRAKE:MDKSA-2003:050 | (as suggested by Vincent Danen of Mandrake)  View
7032  CVE-2003-0204  Candidate  KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF files, related to missing -dPARANOIDSAFER and -dSAFER arguments when using the kghostview Ghostscript viewer.  Assigned (20030414)  NOOP(1) Christey  Christey> MANDRAKE:MDKSA-2003:049 | (as suggested by Vincent Danen of Mandrake)  View

Page 299 of 20943, showing 5 records out of 104715 total, starting on record 1491, ending on 1495

Actions