CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5247 | CVE-2002-0857 | Candidate | Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle DBA system by placing format strings into certain entries in the listener.ora configuration file. | Modified (20050510) | ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(1) Frech | NOOP(3) Christey, Cox, Foat | Christey> XF:oracle-lsnrctl-format-string(9832) | URL:http://www.iss.net/security_center/static/9832.php | CERT-VN:VU#301059 | URL:http://www.kb.cert.org/vuls/id/301059 | BID:5460 | URL:http://www.securityfocus.com/bid/5460 | MISC:http://www.nextgenss.com/advisories/ora-lsnrfmtstr.txt | Frech> XF:oracle-lsnrctl-format-string(9832) | View |
5067 | CVE-2002-0677 | Candidate | CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure. | Modified (20071129) | ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(1) Frech | NOOP(3) Christey, Cox, Foat | Christey> XF:tooltalk-ttdbserverd-ttisclose-validation(9526) | URL:http://www.iss.net/security_center/static/9526.php | BID:5082 | URL:http://www.securityfocus.com/bid/5082 | | HP:HPSBUX0207-199 | URL:http://archives.neohapsis.com/archives/hp/2002-q3/0011.html | Note: while the HP advisory discusses "buffer overflows," | it specifically mentions CA-2002-20, and the text of the | advisory is included in vendor statements for the CERT-VU"s for both | ToolTalk issues covered by CA-2002-20. | | AIXAPAR:IY32368 | URL:http://archives.neohapsis.com/archives/aix/2002-q3/0002.html | AIXAPAR:IY32370 | URL:http://archives.neohapsis.com/archives/aix/2002-q3/0002.html | Christey> HP:HPSBUX0207-199 | URL:http://online.securityfocus.com/advisories/4290 | Christey> SGI:20021101-01-P | Christey> Sun confirmed via email to Matt Wojcik (of MITRE"s OVAL | project) that Sun alert 46022 also addresses this issue. | Frech> XF:tooltalk-ttdbserverd-ttisclose-validation(9526) | View |
8535 | CVE-2004-0107 | Candidate | The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108. | Modified (20100819) | ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(2) Cox, Frech | NOOP(1) Christey | Frech> XF:sysstat-post-trigger-symlink(15428) | http://xforce.iss.net/xforce/xfdb/15428 | Cox> This issue is in the vendor packaging of sysstat, not sysstat itself, | and does not apply to a particular version of upstream | sysstat. Suggest "trigger scripts in various vendors packaging of | syssstat allows local users..." or "in the Red Hat packaging of sysstat" | Christey> CIAC:O-097 | URL:http://www.ciac.org/ciac/bulletins/o-097.shtml | XF:sysstat-post-trigger-symlink(15428) | URL:http://xforce.iss.net/xforce/xfdb/15428 | BID:9838 | URL:http://www.securityfocus.com/bid/9838 | Christey> FEDORA:FEDORA-2004-1372 | URL:https://bugzilla.fedora.us/show_bug.cgi?id=1372 | View |
5050 | CVE-2002-0660 | Candidate | Buffer overflow in libpng 1.0.12-3.woody.2 and libpng3 1.2.1-1.1.woody.2 on Debian GNU/Linux 3.0, and other operating systems, may allow attackers to cause a denial of service and possibly execute arbitrary code, a different vulnerability than CVE-2002-0728. | Modified (20041020) | ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(2) Cox, Frech | NOOP(2) Christey, Foat | Cox> No need to single out woody and Debian Linux, this affects | libpng that is used throughout Linux distributions. | Christey> CALDERA:CSSA-2002-042.0 | URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-042.0.txt | Christey> Need to change desc a bit - say it"s 1.0.12, remove Debian | specifics. | XF:libpng-wide-image-bo(9790) | URL:http://www.iss.net/security_center/static/9790.php | BID:5409 | URL:http://www.securityfocus.com/bid/5409 | CALDERA:CSSA-2002-042.0 | URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-042.0.txt | Frech> XF:libpng-wide-image-bo(9790) | Christey> Change "Debian Linux" to "Debian GNU/Linux" | View |
5089 | CVE-2002-0699 | Candidate | Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user"s system via HTML. | Modified (20061101) | ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(2) Foat, Frech | NOOP(2) Christey, Cox | Foat> Replace the word "Unknown" with "A" and change "allow" to "allows". | Christey> The "Unknown" portion of the vulnerability statement is used | to emphasize that the vendor has not provided sufficient | information to understand the cause or nature of the problem. | This is important because this vagueness makes it difficult | or impossible to resolve it with vulnerability reports | from other sources, increasing the risk of duplication. | | Most candidates affected by CD:VAGUE will use this description | style. | Christey> XF:win-certificate-enrollment-dos(9982) | URL:http://www.iss.net/security_center/static/9982.php | BID:5593 | URL:http://www.securityfocus.com/bid/5593 | Frech> XF:win-certificate-enrollment-dos(9982) | View |
Page 1001 of 20943, showing 5 records out of 104715 total, starting on record 5001, ending on 5005