Show filters
56 Total Results
Displaying 21-30 of 56
Sort by:
Attacker Value
Unknown

CVE-2004-0886

Disclosure Date: January 27, 2005 (last updated February 22, 2025)
Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.
0
Attacker Value
Unknown

CVE-2004-1072

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, may create an interpreter name string that is not NULL terminated, which could cause strings longer than PATH_MAX to be used, leading to buffer overflows that allow local users to cause a denial of service (hang) and possibly execute arbitrary code.
0
Attacker Value
Unknown

CVE-2004-1012

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary code via a certain command ("body[p") that is treated as a different command ("body.peek") and causes an index increment error that leads to an out-of-bounds memory corruption.
0
Attacker Value
Unknown

CVE-2004-0949

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
The smb_recv_trans2 function call in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 does not properly handle the re-assembly of fragmented packets correctly, which could allow remote samba servers to (1) read arbitrary kernel information or (2) raise a counter value to an arbitrary number by sending the first part of the fragmented packet multiple times.
0
Attacker Value
Unknown

CVE-2004-1013

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary code via certain commands such as (1) "body[p", (2) "binary[p", or (3) "binary[p") that cause an index increment error that leads to an out-of-bounds memory corruption.
0
Attacker Value
Unknown

CVE-2004-1071

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly handle a failed call to the mmap function, which causes an incorrect mapped image and may allow local users to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2004-1011

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to execute arbitrary code via a long (1) PROXY or (2) LOGIN command, a different vulnerability than CVE-2004-1015.
0
Attacker Value
Unknown

CVE-2004-1019

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitrary code via untrusted data to the unserialize function that may trigger "information disclosure, double-free and negative reference index array underflow" results.
0
Attacker Value
Unknown

CVE-2004-0883

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Multiple vulnerabilities in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 allow remote samba servers to cause a denial of service (crash) or gain sensitive information from kernel memory via a samba server (1) returning more data than requested to the smb_proc_read function, (2) returning a data offset from outside the samba packet to the smb_proc_readX function, (3) sending a certain TRANS2 fragmented packet to the smb_receive_trans2 function, (4) sending a samba packet with a certain header size to the smb_proc_readX_data function, or (5) sending a certain packet based offset for the data in a packet to the smb_receive_trans2 function.
0
Attacker Value
Unknown

CVE-2004-1065

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary code via a long section name in an image file.
0