CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8918 | CVE-2004-0490 | Candidate | cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which allows local users to execute arbitrary PHP code as other users via a URL that references the attacker"s script after the user"s script, which executes the attacker"s script with the user"s privileges, a different vulnerability than CVE-2004-0529. | Assigned (20040527) | None (candidate not yet proposed) | View | |
8919 | CVE-2004-0491 | Candidate | The linux-2.4.21-mlock.patch in Red Hat Enterprise Linux 3 does not properly maintain the mlock page count when one process unlocks pages that belong to another process, which allows local users to mlock more memory than specified by the rlimit. | Assigned (20040527) | None (candidate not yet proposed) | View | |
8920 | CVE-2004-0492 | Candidate | Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied. | Assigned (20040527) | None (candidate not yet proposed) | View | |
8921 | CVE-2004-0493 | Candidate | The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters. | Assigned (20040527) | None (candidate not yet proposed) | View | |
8922 | CVE-2004-0494 | Candidate | Multiple extfs backend scripts for GNOME virtual file system (VFS) before 1.0.1 may allow remote attackers to perform certain unauthorized actions via a gnome-vfs URI. | Assigned (20040527) | None (candidate not yet proposed) | View |
Page 872 of 20943, showing 5 records out of 104715 total, starting on record 4356, ending on 4360