CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9275  CVE-2004-0847  Candidate  The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "" (backslash) or (2) "%5C" (encoded backslash), aka "Path Validation Vulnerability."  Assigned (20040908)  None (candidate not yet proposed)    View
9276  CVE-2004-0848  Candidate  Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames.  Assigned (20040908)  None (candidate not yet proposed)    View
9266  CVE-2004-0838  Candidate  Lexar Safe Guard for JumpDrive Secure 1.0 stores the password insecurely in memory using XOR encryption, which allows local users to read the password directly from the device and access the password protected part of the drive.  Assigned (20040912)  None (candidate not yet proposed)    View
9277  CVE-2004-0849  Candidate  Integer overflow in the asn_decode_string() function defined in asn1.c in radiusd for GNU Radius 1.1 and 1.2 before 1.2.94, when compiled with the --enable-snmp option, allows remote attackers to cause a denial of service (daemon crash) via certain SNMP requests.  Assigned (20040913)  None (candidate not yet proposed)    View
9278  CVE-2004-0850  Candidate  Star before 1.5_alpha46 does not drop the effective user ID (euid) before calling external programs, which could allow local users to gain privileges by modifying the RSH environment variable to reference a malicious program.  Assigned (20040913)  None (candidate not yet proposed)    View

Page 945 of 20943, showing 5 records out of 104715 total, starting on record 4721, ending on 4725

Actions