CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
7514 | CVE-2003-0690 | Candidate | KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5 module. | Assigned (20030814) | None (candidate not yet proposed) | View | |
7515 | CVE-2003-0691 | Candidate | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not associated with any specific security issue. Notes: none. | Assigned (20030814) | None (candidate not yet proposed) | View | |
7516 | CVE-2003-0692 | Candidate | KDM in KDE 3.1.3 and earlier uses a weak session cookie generation algorithm that does not provide 128 bits of entropy, which allows attackers to guess session cookies via brute force methods and gain access to the user session. | Assigned (20030814) | None (candidate not yet proposed) | View | |
7517 | CVE-2003-0693 | Candidate | A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695. | Assigned (20030814) | None (candidate not yet proposed) | View | |
7518 | CVE-2003-0694 | Candidate | The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c. | Assigned (20030814) | None (candidate not yet proposed) | View |
Page 752 of 20943, showing 5 records out of 104715 total, starting on record 3756, ending on 3760