CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9174  CVE-2004-0746  Candidate  Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, which could allow remote attackers to perform a session fixation attack and hijack a user"s HTTP session.  Assigned (20040726)  None (candidate not yet proposed)    View
9175  CVE-2004-0747  Candidate  Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.  Assigned (20040726)  None (candidate not yet proposed)    View
9176  CVE-2004-0748  Candidate  mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child process to enter an infinite loop.  Assigned (20040726)  None (candidate not yet proposed)    View
9177  CVE-2004-0749  Candidate  The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow remote attackers to gain sensitive information via (1) svn log -v, (2) svn propget, or (3) svn blame, and other commands that follow renames.  Assigned (20040726)  None (candidate not yet proposed)    View
9178  CVE-2004-0750  Candidate  Unknown vulnerability in redhat-config-nfs before 1.0.13, when shares are exported to multiple hosts, can produce incorrect permissions and prevent the all_squash option from being applied.  Assigned (20040726)  None (candidate not yet proposed)    View

Page 924 of 20943, showing 5 records out of 104715 total, starting on record 4616, ending on 4620

Actions