CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9453  CVE-2004-1025  Candidate  Multiple heap-based buffer overflows in imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files.  Assigned (20041112)  None (candidate not yet proposed)    View
9454  CVE-2004-1026  Candidate  Multiple integer overflows in the image handler for imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files.  Assigned (20041112)  None (candidate not yet proposed)    View
9455  CVE-2004-1027  Candidate  Directory traversal vulnerability in the -x (extract) command line option in unarj allows remote attackers to overwrite arbitrary files via an arj archive with filenames that contain .. (dot dot) sequences.  Assigned (20041112)  None (candidate not yet proposed)    View
9456  CVE-2004-1028  Candidate  Untrusted execution path vulnerability in chcod on AIX IBM 5.1.0, 5.2.0, and 5.3.0 allows local users to execute arbitrary programs by modifying the PATH environment variable to point to a malicious "grep" program, which is executed from chcod.  Assigned (20041112)  None (candidate not yet proposed)    View
9457  CVE-2004-1029  Candidate  The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.  Assigned (20041112)  None (candidate not yet proposed)    View

Page 981 of 20943, showing 5 records out of 104715 total, starting on record 4901, ending on 4905

Actions