CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9344 | CVE-2004-0916 | Candidate | Directory traversal vulnerability in cabextract before 1.1 allows remote attackers to overwrite arbitrary files via a cabinet file containing .. (dot dot) sequences in a filename. | Assigned (20040927) | None (candidate not yet proposed) | View | |
9345 | CVE-2004-0917 | Candidate | The default installation of Vignette Application Portal installs the diagnostic utility without authentication requirements, which allows remote attackers to gain sensitive information, such as server and OS version, and conduct unauthorized activities via an HTTP request to /diag. | Assigned (20040927) | None (candidate not yet proposed) | View | |
9346 | CVE-2004-0918 | Candidate | The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger a memory allocation error. | Assigned (20040927) | None (candidate not yet proposed) | View | |
9347 | CVE-2004-0919 | Candidate | The syscons CONS_SCRSHOT ioctl in FreeBSD 5.x allows local users to read arbitrary kernel memory via (1) negative coordinates or (2) large coordinates. | Assigned (20040927) | None (candidate not yet proposed) | View | |
9348 | CVE-2004-0920 | Candidate | Symantec Norton AntiVirus 2004, and earlier versions, allows a virus or other malicious code to avoid detection or cause a denial of service (application crash) using a filename containing an MS-DOS device name. | Assigned (20040927) | None (candidate not yet proposed) | View |
Page 959 of 20943, showing 5 records out of 104715 total, starting on record 4791, ending on 4795