CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9344  CVE-2004-0916  Candidate  Directory traversal vulnerability in cabextract before 1.1 allows remote attackers to overwrite arbitrary files via a cabinet file containing .. (dot dot) sequences in a filename.  Assigned (20040927)  None (candidate not yet proposed)    View
9345  CVE-2004-0917  Candidate  The default installation of Vignette Application Portal installs the diagnostic utility without authentication requirements, which allows remote attackers to gain sensitive information, such as server and OS version, and conduct unauthorized activities via an HTTP request to /diag.  Assigned (20040927)  None (candidate not yet proposed)    View
9346  CVE-2004-0918  Candidate  The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger a memory allocation error.  Assigned (20040927)  None (candidate not yet proposed)    View
9347  CVE-2004-0919  Candidate  The syscons CONS_SCRSHOT ioctl in FreeBSD 5.x allows local users to read arbitrary kernel memory via (1) negative coordinates or (2) large coordinates.  Assigned (20040927)  None (candidate not yet proposed)    View
9348  CVE-2004-0920  Candidate  Symantec Norton AntiVirus 2004, and earlier versions, allows a virus or other malicious code to avoid detection or cause a denial of service (application crash) using a filename containing an MS-DOS device name.  Assigned (20040927)  None (candidate not yet proposed)    View

Page 959 of 20943, showing 5 records out of 104715 total, starting on record 4791, ending on 4795

Actions