CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8790  CVE-2004-0362  Candidate  Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various RealSecure, Proventia, and BlackICE products, allow remote attackers to execute arbitrary code via a SRV_MULTI response containing a SRV_USER_ONLINE response packet and a SRV_META_USER response packet with long (1) nickname, (2) firstname, (3) lastname, or (4) email address fields, as exploited by the Witty worm.  Assigned (20040318)  None (candidate not yet proposed)    View
8791  CVE-2004-0363  Candidate  Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execute arbitrary code via a long parameter to the LaunchCustomRuleWizard method.  Assigned (20040319)  None (candidate not yet proposed)    View
8792  CVE-2004-0364  Candidate  The WrapNISUM ActiveX component (WrapUM.dll) in Norton Internet Security 2004 is marked safe for scripting, which allows remote attackers to execute arbitrary programs via the LaunchURL method.  Assigned (20040319)  None (candidate not yet proposed)    View
8793  CVE-2004-0365  Candidate  The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.  Assigned (20040322)  None (candidate not yet proposed)    View
8794  CVE-2004-0366  Candidate  SQL injection vulnerability in the libpam-pgsql library before 0.5.2 allows attackers to execute arbitrary SQL statements.  Assigned (20040322)  None (candidate not yet proposed)    View

Page 845 of 20943, showing 5 records out of 104715 total, starting on record 4221, ending on 4225

Actions