CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9065  CVE-2004-0637  Candidate  Oracle Database Server 8.1.7.4 through 9.2.0.4 allows local users to execute commands with additional privileges via the ctxsys.driload package, which is publicly accessible.  Assigned (20040707)  None (candidate not yet proposed)    View
9066  CVE-2004-0638  Candidate  Buffer overflow in the KSDWRTB function in the dbms_system package (dbms_system.ksdwrt) for Oracle 9i Database Server Release 2 9.2.0.3 and 9.2.0.4, 9i Release 1 9.0.1.4 and 9.0.1.5, and 8i Release 1 8.1.7.4, allows remote authorized users to execute arbitrary code via a long second argument.  Assigned (20040707)  None (candidate not yet proposed)    View
9067  CVE-2004-0639  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or script via (1) the $mailer variable in read_body.php, (2) the $senderNames_part variable in mailbox_display.php, and possibly other vectors including (3) the $event_title variable or (4) the $event_text variable.  Assigned (20040708)  None (candidate not yet proposed)    View
9068  CVE-2004-0640  Candidate  Format string vulnerability in the SSL_set_verify function in telnetd.c for SSLtelnet daemon (SSLtelnetd) 0.13 allows remote attackers to execute arbitrary code.  Assigned (20040708)  None (candidate not yet proposed)    View
9069  CVE-2004-0641  Candidate  Thomson SpeedTouch 510 ADSL Router with firmware GV8BAA3.270, and possibly earlier versions, generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.  Assigned (20040708)  None (candidate not yet proposed)    View

Page 902 of 20943, showing 5 records out of 104715 total, starting on record 4506, ending on 4510

Actions