CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7514  CVE-2003-0690  Candidate  KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5 module.  Assigned (20030814)  None (candidate not yet proposed)    View
7515  CVE-2003-0691  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not associated with any specific security issue. Notes: none.  Assigned (20030814)  None (candidate not yet proposed)    View
7516  CVE-2003-0692  Candidate  KDM in KDE 3.1.3 and earlier uses a weak session cookie generation algorithm that does not provide 128 bits of entropy, which allows attackers to guess session cookies via brute force methods and gain access to the user session.  Assigned (20030814)  None (candidate not yet proposed)    View
7517  CVE-2003-0693  Candidate  A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695.  Assigned (20030814)  None (candidate not yet proposed)    View
7518  CVE-2003-0694  Candidate  The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.  Assigned (20030814)  None (candidate not yet proposed)    View

Page 752 of 20943, showing 5 records out of 104715 total, starting on record 3756, ending on 3760

Actions