Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown

CVE-2004-0414

Disclosure Date: August 06, 2004 (last updated February 22, 2025)
CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of critical program data, or arbitrary code execution.
0
Attacker Value
Unknown

CVE-2004-0396

Disclosure Date: June 14, 2004 (last updated February 22, 2025)
Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers to execute arbitrary code via Entry lines.
0
Attacker Value
Unknown

CVE-2003-0977

Disclosure Date: January 05, 2004 (last updated February 22, 2025)
CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via malformed module requests.
0
Attacker Value
Unknown

CVE-2003-0015

Disclosure Date: February 07, 2003 (last updated February 22, 2025)
Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-prog and Checkin-prog commands.
0