CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7446  CVE-2003-0619  Candidate  Integer signedness error in the decode_fh function of nfs3xdr.c in Linux kernel before 2.4.21 allows remote attackers to cause a denial of service (kernel panic) via a negative size value within XDR data of an NFSv3 procedure call.  Assigned (20030731)  None (candidate not yet proposed)    View
7447  CVE-2003-0620  Candidate  Multiple buffer overflows in man-db 2.4.1 and earlier, when installed setuid, allow local users to gain privileges via (1) MANDATORY_MANPATH, MANPATH_MAP, and MANDB_MAP arguments to add_to_dirlist in manp.c, (2) a long pathname to ult_src in ult_src.c, (3) a long .so argument to test_for_include in ult_src.c, (4) a long MANPATH environment variable, or (5) a long PATH environment variable.  Assigned (20030731)  None (candidate not yet proposed)    View
7448  CVE-2003-0621  Candidate  The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to determine the existence of files outside the web root via modified paths in the INIFILE argument.  Assigned (20030731)  None (candidate not yet proposed)    View
7449  CVE-2003-0622  Candidate  The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to cause a denial of service (hang) via pathname arguments that contain MS-DOS device names such as CON and AUX.  Assigned (20030731)  None (candidate not yet proposed)    View
7450  CVE-2003-0623  Candidate  Cross-site scripting (XSS) vulnerability in the Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to inject arbitrary web script via the INIFILE argument.  Assigned (20030731)  None (candidate not yet proposed)    View

Page 738 of 20943, showing 5 records out of 104715 total, starting on record 3686, ending on 3690

Actions