CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9453 | CVE-2004-1025 | Candidate | Multiple heap-based buffer overflows in imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files. | Assigned (20041112) | None (candidate not yet proposed) | View | |
9454 | CVE-2004-1026 | Candidate | Multiple integer overflows in the image handler for imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files. | Assigned (20041112) | None (candidate not yet proposed) | View | |
9455 | CVE-2004-1027 | Candidate | Directory traversal vulnerability in the -x (extract) command line option in unarj allows remote attackers to overwrite arbitrary files via an arj archive with filenames that contain .. (dot dot) sequences. | Assigned (20041112) | None (candidate not yet proposed) | View | |
9456 | CVE-2004-1028 | Candidate | Untrusted execution path vulnerability in chcod on AIX IBM 5.1.0, 5.2.0, and 5.3.0 allows local users to execute arbitrary programs by modifying the PATH environment variable to point to a malicious "grep" program, which is executed from chcod. | Assigned (20041112) | None (candidate not yet proposed) | View | |
9457 | CVE-2004-1029 | Candidate | The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages. | Assigned (20041112) | None (candidate not yet proposed) | View |
Page 981 of 20943, showing 5 records out of 104715 total, starting on record 4901, ending on 4905