CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9212  CVE-2004-0784  Candidate  The smiley theme functionality in Gaim before 0.82 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of the tar file that is dragged to the smiley selector.  Assigned (20040817)  None (candidate not yet proposed)    View
9213  CVE-2004-0785  Candidate  Multiple buffer overflows in Gaim before 0.82 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) Rich Text Format (RTF) messages, (2) a long hostname for the local system as obtained from DNS, or (3) a long URL that is not properly handled by the URL decoder.  Assigned (20040817)  None (candidate not yet proposed)    View
9214  CVE-2004-0786  Candidate  The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool.  Assigned (20040817)  None (candidate not yet proposed)    View
9215  CVE-2004-0787  Candidate  Cross-site scripting (XSS) vulnerability in the web frontend in OpenCA 0.9.1-8 and earlier, and 0.9.2 RC6 and earlier, allows remote attackers to inject arbitrary web script or HTML via the form input fields.  Assigned (20040817)  None (candidate not yet proposed)    View
9223  CVE-2004-0795  Candidate  DB2 8.1 remote command server (DB2RCMD.EXE) executes the db2rcmdc.exe program as the db2admin administrator, which allows local users to gain privileges via the DB2REMOTECMD named pipe.  Assigned (20040819)  None (candidate not yet proposed)    View

Page 933 of 20943, showing 5 records out of 104715 total, starting on record 4661, ending on 4665

Actions