CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9384 | CVE-2004-0956 | Candidate | MySQL before 4.0.20 allows remote attackers to cause a denial of service (application crash) via a MATCH AGAINST query with an opening double quote but no closing double quote. | Assigned (20041013) | None (candidate not yet proposed) | View | |
9385 | CVE-2004-0957 | Candidate | Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized activities. | Assigned (20041013) | None (candidate not yet proposed) | View | |
9386 | CVE-2004-0958 | Candidate | php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC variables that end in an open bracket character, which causes PHP to calculate an incorrect string length. | Assigned (20041013) | None (candidate not yet proposed) | View | |
9387 | CVE-2004-0959 | Candidate | rfc1867.c in PHP before 5.0.2 allows local users to upload files to arbitrary locations via a PHP script with a certain MIME header that causes the "$_FILES" array to be modified. | Assigned (20041013) | None (candidate not yet proposed) | View | |
4216 | CVE-2001-1413 | Candidate | Stack-based buffer overflow in the comprexx function for ncompress 4.2.4 and earlier, when used in situations that cross security boundaries (such as FTP server), may allow remote attackers to execute arbitrary code via a long filename argument. | Assigned (20041018) | None (candidate not yet proposed) | View |
Page 967 of 20943, showing 5 records out of 104715 total, starting on record 4831, ending on 4835