CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8845  CVE-2004-0417  Candidate  Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could cause temporary data to remain undeleted and consume disk space.  Assigned (20040416)  None (candidate not yet proposed)    View
8846  CVE-2004-0418  Candidate  serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data.  Assigned (20040416)  None (candidate not yet proposed)    View
8847  CVE-2004-0419  Candidate  XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0, which could allow remote attackers to connect to the port, in violation of the intended restrictions.  Assigned (20040416)  None (candidate not yet proposed)    View
8848  CVE-2004-0420  Candidate  The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.  Assigned (20040419)  None (candidate not yet proposed)    View
8849  CVE-2004-0421  Candidate  The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that triggers an error that causes an out-of-bounds read when creating the error message.  Assigned (20040419)  None (candidate not yet proposed)    View

Page 856 of 20943, showing 5 records out of 104715 total, starting on record 4276, ending on 4280

Actions