CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9259 | CVE-2004-0831 | Candidate | McAfee VirusScan 4.5.1 does not drop SYSTEM privileges before allowing users to browse for files via the "System Scan" properties of the System Tray applet, which could allow local users to gain privileges. | Assigned (20040907) | None (candidate not yet proposed) | View | |
9260 | CVE-2004-0832 | Candidate | The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled, allow remote attackers to cause a denial of service (application crash) via an NTLMSSP packet that causes a negative value to be passed to memcpy. | Assigned (20040908) | None (candidate not yet proposed) | View | |
9261 | CVE-2004-0833 | Candidate | Sendmail before 8.12.3 on Debian GNU/Linux, when using sasl and sasl-bin, uses a Sendmail configuration script with a fixed username and password, which could allow remote attackers to use Sendmail as an open mail relay and send spam messages. | Assigned (20040908) | None (candidate not yet proposed) | View | |
9262 | CVE-2004-0834 | Candidate | Format string vulnerability in Speedtouch USB driver before 1.3.1 allows local users to execute arbitrary code via (1) modem_run, (2) pppoa2, or (3) pppoa3. | Assigned (20040908) | None (candidate not yet proposed) | View | |
9263 | CVE-2004-0835 | Candidate | MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities. | Assigned (20040908) | None (candidate not yet proposed) | View |
Page 942 of 20943, showing 5 records out of 104715 total, starting on record 4706, ending on 4710