NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
71230  CVE-2004-0806  cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, which allows local users to gain privileges.    7.2  High  2017-07-18  2017-07-10  View
71486  CVE-2004-1094  Buffer overflow in InnerMedia DynaZip DUNZIP32.dll file version 5.00.03 and earlier allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, as demonstrated using (1) a .rjs (skin) file in RealPlayer 10 through RealPlayer 10.5 (6.0.12.1053), RealOne Player 1 and 2, (2) the Restore Backup function in CheckMark Software Payroll 2004/2005 3.9.6 and earlier, (3) CheckMark MultiLedger before 7.0.2, (4) dtSearch 6.x and 7.x, (5) mcupdmgr.exe and mghtml.exe in McAfee VirusScan 10 Build 10.0.21 and earlier, (6) IBM Lotus Notes before 6.5.5, and other products. NOTE: it is unclear whether this is the same vulnerability as CVE-2004-0575, although the data manipulations are the same.    10  High  2017-07-18  2017-07-10  View
71742  CVE-2004-1363  Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed.    7.2  High  2017-07-18  2017-07-10  View
71998  CVE-2004-1619  Buffer overflow in Privateer's Bounty: Age of Sail II allows remote attackers to execute arbitrary code via a long nickname.    7.5  High  2017-07-18  2017-07-10  View
72254  CVE-2004-1876  The "%f" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) before 0.70 allows local users to execute arbitrary commands via shell metacharacters in a file name.    4.6  Medium  2017-07-18  2017-07-10  View

Page 16706 of 17672, showing 5 records out of 88360 total, starting on record 83526, ending on 83530

Actions