CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9384  CVE-2004-0956  Candidate  MySQL before 4.0.20 allows remote attackers to cause a denial of service (application crash) via a MATCH AGAINST query with an opening double quote but no closing double quote.  Assigned (20041013)  None (candidate not yet proposed)    View
9385  CVE-2004-0957  Candidate  Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized activities.  Assigned (20041013)  None (candidate not yet proposed)    View
9386  CVE-2004-0958  Candidate  php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC variables that end in an open bracket character, which causes PHP to calculate an incorrect string length.  Assigned (20041013)  None (candidate not yet proposed)    View
9387  CVE-2004-0959  Candidate  rfc1867.c in PHP before 5.0.2 allows local users to upload files to arbitrary locations via a PHP script with a certain MIME header that causes the "$_FILES" array to be modified.  Assigned (20041013)  None (candidate not yet proposed)    View
4216  CVE-2001-1413  Candidate  Stack-based buffer overflow in the comprexx function for ncompress 4.2.4 and earlier, when used in situations that cross security boundaries (such as FTP server), may allow remote attackers to execute arbitrary code via a long filename argument.  Assigned (20041018)  None (candidate not yet proposed)    View

Page 967 of 20943, showing 5 records out of 104715 total, starting on record 4831, ending on 4835

Actions