CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8712 | CVE-2004-0284 | Candidate | Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name. | Proposed (20040318) | ACCEPT(1) Cole | NOOP(3) Armstrong, Christey, Cox | REVIEWING(1) Wall | Christey> MISC:http://www.acrossecurity.com/aspr/ASPR-2004-01-20-1-PUB.txt | View |
2487 | CVE-2000-0918 | Candidate | Format string vulnerability in kvt in KDE 1.1.2 may allow local users to execute arbitrary commands via a DISPLAY environmental variable that contains formatting characters. | Proposed (20001129) | ACCEPT(2) Baker, Mell | NOOP(2) Cole, Wall | REVIEWING(1) Christey | Christey> May be a duplicate of CVE-2000-0373, but the ref"s in that CVE | are vague. I suspect this *isn"t* a duplicate because this is | a format string problem. | Baker> I think it is sufficiently different from 2000-0373. | View |
6912 | CVE-2003-0083 | Candidate | Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020. | Assigned (20030210) | NOOP(1) Christey | Christey> MANDRAKE:MDKSA-2003:050 | (as suggested by Vincent Danen of Mandrake) | View |
6961 | CVE-2003-0132 | Candidate | A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed. | Assigned (20030313) | NOOP(1) Christey | Christey> MANDRAKE:MDKSA-2003:050 | (as suggested by Vincent Danen of Mandrake) | View |
7032 | CVE-2003-0204 | Candidate | KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF files, related to missing -dPARANOIDSAFER and -dSAFER arguments when using the kghostview Ghostscript viewer. | Assigned (20030414) | NOOP(1) Christey | Christey> MANDRAKE:MDKSA-2003:049 | (as suggested by Vincent Danen of Mandrake) | View |
Page 299 of 20943, showing 5 records out of 104715 total, starting on record 1491, ending on 1495