CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8435  CVE-2004-0007  Candidate  Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code.  Modified (20100819)  ACCEPT(5) Armstrong, Baker, Cole, Cox, Green | NOOP(2) Christey, Wall  Christey> Normalize Gentoo, Slackware reference | Christey> CERT-VN:VU#197142  View
8436  CVE-2004-0008  Candidate  Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.  Modified (20100819)  ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | NOOP(1) Christey  Christey> CERT-VN:VU#779614  View
7421  CVE-2003-0594  Candidate  Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.  Modified (20100819)  ACCEPT(5) Armstrong, Baker, Balinsky, Cole, Cox | MODIFY(1) Frech | NOOP(1) Wall | REVIEWING(1) Christey  Christey> REDHAT:RHSA-2004:112 | URL:http://www.redhat.com/support/errata/RHSA-2004-112.html | Frech> XF:web-browser-cookie-bypass(15424) | http://xforce.iss.net/xforce/xfdb/15424 | Cox> Addref: REDHAT:RHSA-2004:112 | Christey> REDHAT:RHSA-2004:110 | URL:http://www.redhat.com/support/errata/RHSA-2004-110.html | Balinsky> Link in References. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> Consider whether this is really a design-level problem that applies to | the interaction between any vulnerable XSS, its associated domain, and | any web browser, because browsers enforce security boundaries at the | domain level. If so, then the "%2e%2e" problem may be a red herring, | or a single attack vector of any number of vectors. | | CVE-2003-0513, CVE-2003-0514, CVE-2003-0592, CVE-2003-0593, | and CVE-2003-0594 all cover this specific issue (each for a | different browser). | Christey> HP:SSRT4722 | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108448379429944&w=2 | Christey> FEDORA:FLSA:2089 | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109900315219363&w=2  View
4791  CVE-2002-0399  Candidate  Directory traversal vulnerability in GNU tar 1.13.19 through 1.13.25, and possibly later versions, allows attackers to overwrite arbitrary files during archive extraction via a (1) "/.." or (2) "./.." string, which removes the leading slash but leaves the "..", a variant of CVE-2001-1267.  Modified (20100521)  ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Cox | NOOP(1) Christey  Christey> MANDRAKE:MDKSA-2002:066 | Cox> Addref: RHSA-2002:138  View
4557  CVE-2002-0164  Candidate  Vulnerability in the MIT-SHM extension of the X server on Linux (XFree86) 4.2.1 and earlier allows local users to read and write arbitrary shared memory, possibly to cause a denial of service or gain privileges.  Modified (20100521)  ACCEPT(5) Armstrong, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(2) Christey, Foat  Christey> SGI:20021001-01-P | Christey> BUGTRAQ:20021024 GLSA: xfree | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=103547625009363&w=2 | | This Gentoo advisory mentions XFree86 4.2.0-r12 and earlier. | Frech> XF:xfree86-mitshm-memory-access(8706) | Christey> REDHAT:RHSA-2003:067 | URL:http://www.redhat.com/support/errata/RHSA-2003-067.html | Christey> Add something like "Xfree86 before 4.2.1" to the description. | | The affected versions aren"t quite clear, as various vendor | advisories list different versions. | Christey> DEBIAN:DSA-380 | Christey> CALDERA:CSSA-2003-SCO.26  View

Page 433 of 20943, showing 5 records out of 104715 total, starting on record 2161, ending on 2165

Actions