CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8540 | CVE-2004-0112 | Candidate | The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read. | Assigned (20040202) | None (candidate not yet proposed) | View | |
8544 | CVE-2004-0116 | Candidate | An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field. | Assigned (20040203) | None (candidate not yet proposed) | View | |
8545 | CVE-2004-0117 | Candidate | Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code. | Assigned (20040203) | None (candidate not yet proposed) | View | |
8546 | CVE-2004-0118 | Candidate | The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code. | Assigned (20040203) | None (candidate not yet proposed) | View | |
8547 | CVE-2004-0119 | Candidate | The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection. | Assigned (20040203) | None (candidate not yet proposed) | View |
Page 825 of 20943, showing 5 records out of 104715 total, starting on record 4121, ending on 4125