CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9757  CVE-2004-1329  Candidate  Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 5.1 through 5.3 allows local users to execute arbitrary programs by modifying the DIAGNOSTICS environment variable to point to a malicious Dctrl program.  Assigned (20050106)  None (candidate not yet proposed)    View
9482  CVE-2004-1054  Candidate  Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying the PATH environment variable to point to a malicious "uname" program, which is executed from lsvpd after lsvpd has been invoked by invscout.  Assigned (20041118)  None (candidate not yet proposed)    View
9456  CVE-2004-1028  Candidate  Untrusted execution path vulnerability in chcod on AIX IBM 5.1.0, 5.2.0, and 5.3.0 allows local users to execute arbitrary programs by modifying the PATH environment variable to point to a malicious "grep" program, which is executed from chcod.  Assigned (20041112)  None (candidate not yet proposed)    View
27603  CVE-2007-4246  Candidate  Unspecified vulnerability, possibly a buffer overflow, in Justsystem Ichitaro 2007 and earlier allows remote attackers to execute arbitrary code via a modified document, as actively exploited in August 2007 by malware such as Tarodrop.D (Tarodrop.Q), a different vulnerability than CVE-2006-4326, CVE-2006-5424, CVE-2006-6400, and CVE-2007-1938.  Assigned (20070808)  None (candidate not yet proposed)    View
16426  CVE-2006-0322  Candidate  Unspecified vulnerability the edit comment formatting functionality in MediaWiki 1.5.x before 1.5.6 and 1.4.x before 1.4.14 allows attackers to cause a denial of service (infinite loop) via "certain malformed links."  Assigned (20060119)  None (candidate not yet proposed)    View

Page 891 of 20943, showing 5 records out of 104715 total, starting on record 4451, ending on 4455

Actions