CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9493 | CVE-2004-1065 | Candidate | Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary code via a long section name in an image file. | Assigned (20041123) | None (candidate not yet proposed) | View | |
9494 | CVE-2004-1066 | Candidate | The cmdline pseudofiles in (1) procfs on FreeBSD 4.8 through 5.3, and (2) linprocfs on FreeBSD 5.x through 5.3, do not properly validate a process argument vector, which allows local users to cause a denial of service (panic) or read portions of kernel memory. NOTE: this candidate might be SPLIT into 2 separate items in the future. | Assigned (20041129) | None (candidate not yet proposed) | View | |
9495 | CVE-2004-1067 | Candidate | Off-by-one error in the mysasl_canon_user function in Cyrus IMAP Server 2.2.9 and earlier leads to a buffer overflow, which may allow remote attackers to execute arbitrary code via the username. | Assigned (20041129) | None (candidate not yet proposed) | View | |
9496 | CVE-2004-1068 | Candidate | A "missing serialization" error in the unix_dgram_recvmsg function in Linux 2.4.27 and earlier, and 2.6.x up to 2.6.9, allows local users to gain privileges via a race condition. | Assigned (20041129) | None (candidate not yet proposed) | View | |
9497 | CVE-2004-1069 | Candidate | Race condition in SELinux 2.6.x through 2.6.9 allows local users to cause a denial of service (kernel crash) via SOCK_SEQPACKET unix domain sockets, which are not properly handled in the sock_dgram_sendmsg function. | Assigned (20041129) | None (candidate not yet proposed) | View |
Page 989 of 20943, showing 5 records out of 104715 total, starting on record 4941, ending on 4945