Show filters
29 Total Results
Displaying 11-20 of 29
Sort by:
Attacker Value
Unknown

CVE-2004-1471

Disclosure Date: December 31, 2004 (last updated October 04, 2023)
Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commit access to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a wrapper line.
0
Attacker Value
Unknown

CVE-2004-2230

Disclosure Date: December 31, 2004 (last updated October 04, 2023)
Heap-based buffer overflow in isakmpd on OpenBSD 3.4 through 3.6 allows local users to cause a denial of service (panic) and corrupt memory via IPSEC credentials on a socket.
0
Attacker Value
Unknown

CVE-2004-2163

Disclosure Date: December 31, 2004 (last updated October 04, 2023)
login_radius on OpenBSD 3.2, 3.5, and possibly other versions does not verify the shared secret in a response packet from a RADIUS server, which allows remote attackers to bypass authentication by spoofing server replies.
0
Attacker Value
Unknown

CVE-2004-0688

Disclosure Date: October 20, 2004 (last updated October 04, 2023)
Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to execute arbitrary code via a malformed XPM image file.
0
Attacker Value
Unknown

CVE-2004-0687

Disclosure Date: October 20, 2004 (last updated October 04, 2023)
Multiple stack-based buffer overflows in (1) xpmParseColors in parse.c, (2) ParseAndPutPixels in create.c, and (3) ParsePixels in parse.c for libXpm before 6.8.1 allow remote attackers to execute arbitrary code via a malformed XPM image file.
0
Attacker Value
Unknown

CVE-2004-0819

Disclosure Date: August 25, 2004 (last updated October 04, 2023)
The bridge functionality in OpenBSD 3.4 and 3.5, when running a gateway configured as a bridging firewall with the link2 option for IPSec enabled, allows remote attackers to cause a denial of service (crash) via an ICMP echo (ping) packet.
0
Attacker Value
Unknown

CVE-2004-0417

Disclosure Date: August 06, 2004 (last updated October 04, 2023)
Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could cause temporary data to remain undeleted and consume disk space.
0
Attacker Value
Unknown

CVE-2004-0416

Disclosure Date: August 06, 2004 (last updated October 04, 2023)
Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2004-0418

Disclosure Date: August 06, 2004 (last updated October 04, 2023)
serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data.
0
Attacker Value
Unknown

CVE-2004-0414

Disclosure Date: August 06, 2004 (last updated October 03, 2023)
CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of critical program data, or arbitrary code execution.
0