CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9259  CVE-2004-0831  Candidate  McAfee VirusScan 4.5.1 does not drop SYSTEM privileges before allowing users to browse for files via the "System Scan" properties of the System Tray applet, which could allow local users to gain privileges.  Assigned (20040907)  None (candidate not yet proposed)    View
9260  CVE-2004-0832  Candidate  The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled, allow remote attackers to cause a denial of service (application crash) via an NTLMSSP packet that causes a negative value to be passed to memcpy.  Assigned (20040908)  None (candidate not yet proposed)    View
9261  CVE-2004-0833  Candidate  Sendmail before 8.12.3 on Debian GNU/Linux, when using sasl and sasl-bin, uses a Sendmail configuration script with a fixed username and password, which could allow remote attackers to use Sendmail as an open mail relay and send spam messages.  Assigned (20040908)  None (candidate not yet proposed)    View
9262  CVE-2004-0834  Candidate  Format string vulnerability in Speedtouch USB driver before 1.3.1 allows local users to execute arbitrary code via (1) modem_run, (2) pppoa2, or (3) pppoa3.  Assigned (20040908)  None (candidate not yet proposed)    View
9263  CVE-2004-0835  Candidate  MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.  Assigned (20040908)  None (candidate not yet proposed)    View

Page 942 of 20943, showing 5 records out of 104715 total, starting on record 4706, ending on 4710

Actions