CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6968  CVE-2003-0139  Candidate  Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and "ticket splicing."  Assigned (20030313)  NOOP(1) Christey  Christey> MANDRAKE:MDKSA-2003:043 | (as suggested by Vincent Danen of Mandrake)  View
6969  CVE-2003-0140  Candidate  Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder.  Assigned (20030313)  None (candidate not yet proposed)    View
6970  CVE-2003-0141  Candidate  The PNG deflate algorithm in RealOne Player 6.0.11.x and earlier, RealPlayer 8/RealPlayer Plus 8 6.0.9.584, and other versions allows remote attackers to corrupt the heap and overwrite arbitrary memory via a PNG graphic file format containing compressed data using fixed trees that contain the length values 286-287, which are treated as a very large length.  Assigned (20030313)  None (candidate not yet proposed)    View
6971  CVE-2003-0142  Candidate  Adobe Acrobat Reader (acroread) 6, under certain circumstances when running with the "Certified plug-ins only" option disabled, loads plug-ins with signatures used for older versions of Acrobat, which can allow attackers to cause Acrobat to enter Certified mode and run untrusted plugins by modifying the CTIsCertifiedMode function.  Assigned (20030313)  None (candidate not yet proposed)    View
6977  CVE-2003-0148  Candidate  The default installation of MSDE via McAfee ePolicy Orchestrator 2.0 through 3.0 allows attackers to execute arbitrary code via a series of steps that (1) obtain the database administrator username and encrypted password in a configuration file from the ePO server using a certain request, (2) crack the password due to weak cryptography, and (3) use the password to pass commands through xp_cmdshell.  Assigned (20030317)  None (candidate not yet proposed)    View

Page 643 of 20943, showing 5 records out of 104715 total, starting on record 3211, ending on 3215

Actions