CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8969  CVE-2004-0541  Candidate  Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable).  Assigned (20040604)  None (candidate not yet proposed)    View
8958  CVE-2004-0530  Candidate  The PHP package in Slackware 8.1, 9.0, and 9.1, when linked against a static library, includes /tmp in the search path, which allows local users to execute arbitrary code as the PHP user by inserting shared libraries into the appropriate path.  Assigned (20040604)  None (candidate not yet proposed)    View
8959  CVE-2004-0531  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20040604)  None (candidate not yet proposed)    View
8970  CVE-2004-0542  Candidate  PHP before 4.3.7 on Win32 platforms does not properly filter all shell metacharacters, which allows local or remote attackers to execute arbitrary code, overwrite files, and access internal environment variables via (1) the "%", "|", or ">" characters to the escapeshellcmd function, or (2) the "%" character to the escapeshellarg function.  Assigned (20040608)  None (candidate not yet proposed)    View
8971  CVE-2004-0543  Candidate  Multiple SQL injection vulnerabilities in Oracle Applications 11.0 and Oracle E-Business Suite 11.5.1 through 11.5.8 allow remote attackers to execute arbitrary SQL procedures and queries.  Assigned (20040608)  None (candidate not yet proposed)    View

Page 882 of 20943, showing 5 records out of 104715 total, starting on record 4406, ending on 4410

Actions