Show filters
205 Total Results
Displaying 181-190 of 205
Sort by:
Attacker Value
Unknown
CVE-2004-0416
Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2004-0548
Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Multiple stack-based buffer overflows in the word-list-compress functionality in compress.c for Aspell allow local users to execute arbitrary code via a long entry in the wordlist that is not properly handled when using the (1) "c" compress option or (2) "d" decompress option.
0
Attacker Value
Unknown
CVE-2004-0557
Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to execute arbitrary code via certain WAV file header fields.
0
Attacker Value
Unknown
CVE-2004-0649
Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Buffer overflow in write_packet in control.c for l2tpd may allow remote attackers to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2004-0418
Disclosure Date: August 06, 2004 (last updated February 22, 2025)
serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data.
0
Attacker Value
Unknown
CVE-2004-0667
Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Rule Set Based Access Control (RSBAC) 1.2.2 through 1.2.3 allows access to sys_creat, sys_open, and sys_mknod inside jails, which could allow local users to gain elevated privileges.
0
Attacker Value
Unknown
CVE-2004-0414
Disclosure Date: August 06, 2004 (last updated February 22, 2025)
CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of critical program data, or arbitrary code execution.
0
Attacker Value
Unknown
CVE-2004-0554
Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a "crash.c" program.
0
Attacker Value
Unknown
CVE-2004-0493
Disclosure Date: August 06, 2004 (last updated February 22, 2025)
The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters.
0
Attacker Value
Unknown
CVE-2004-0535
Disclosure Date: August 06, 2004 (last updated February 22, 2025)
The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this issue was originally incorrectly reported as a "buffer overflow" by some sources.
0