CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5247  CVE-2002-0857  Candidate  Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle DBA system by placing format strings into certain entries in the listener.ora configuration file.  Modified (20050510)  ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(1) Frech | NOOP(3) Christey, Cox, Foat  Christey> XF:oracle-lsnrctl-format-string(9832) | URL:http://www.iss.net/security_center/static/9832.php | CERT-VN:VU#301059 | URL:http://www.kb.cert.org/vuls/id/301059 | BID:5460 | URL:http://www.securityfocus.com/bid/5460 | MISC:http://www.nextgenss.com/advisories/ora-lsnrfmtstr.txt | Frech> XF:oracle-lsnrctl-format-string(9832)  View
5067  CVE-2002-0677  Candidate  CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.  Modified (20071129)  ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(1) Frech | NOOP(3) Christey, Cox, Foat  Christey> XF:tooltalk-ttdbserverd-ttisclose-validation(9526) | URL:http://www.iss.net/security_center/static/9526.php | BID:5082 | URL:http://www.securityfocus.com/bid/5082 | | HP:HPSBUX0207-199 | URL:http://archives.neohapsis.com/archives/hp/2002-q3/0011.html | Note: while the HP advisory discusses "buffer overflows," | it specifically mentions CA-2002-20, and the text of the | advisory is included in vendor statements for the CERT-VU"s for both | ToolTalk issues covered by CA-2002-20. | | AIXAPAR:IY32368 | URL:http://archives.neohapsis.com/archives/aix/2002-q3/0002.html | AIXAPAR:IY32370 | URL:http://archives.neohapsis.com/archives/aix/2002-q3/0002.html | Christey> HP:HPSBUX0207-199 | URL:http://online.securityfocus.com/advisories/4290 | Christey> SGI:20021101-01-P | Christey> Sun confirmed via email to Matt Wojcik (of MITRE"s OVAL | project) that Sun alert 46022 also addresses this issue. | Frech> XF:tooltalk-ttdbserverd-ttisclose-validation(9526)  View
8535  CVE-2004-0107  Candidate  The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.  Modified (20100819)  ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(2) Cox, Frech | NOOP(1) Christey  Frech> XF:sysstat-post-trigger-symlink(15428) | http://xforce.iss.net/xforce/xfdb/15428 | Cox> This issue is in the vendor packaging of sysstat, not sysstat itself, | and does not apply to a particular version of upstream | sysstat. Suggest "trigger scripts in various vendors packaging of | syssstat allows local users..." or "in the Red Hat packaging of sysstat" | Christey> CIAC:O-097 | URL:http://www.ciac.org/ciac/bulletins/o-097.shtml | XF:sysstat-post-trigger-symlink(15428) | URL:http://xforce.iss.net/xforce/xfdb/15428 | BID:9838 | URL:http://www.securityfocus.com/bid/9838 | Christey> FEDORA:FEDORA-2004-1372 | URL:https://bugzilla.fedora.us/show_bug.cgi?id=1372  View
5050  CVE-2002-0660  Candidate  Buffer overflow in libpng 1.0.12-3.woody.2 and libpng3 1.2.1-1.1.woody.2 on Debian GNU/Linux 3.0, and other operating systems, may allow attackers to cause a denial of service and possibly execute arbitrary code, a different vulnerability than CVE-2002-0728.  Modified (20041020)  ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(2) Cox, Frech | NOOP(2) Christey, Foat  Cox> No need to single out woody and Debian Linux, this affects | libpng that is used throughout Linux distributions. | Christey> CALDERA:CSSA-2002-042.0 | URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-042.0.txt | Christey> Need to change desc a bit - say it"s 1.0.12, remove Debian | specifics. | XF:libpng-wide-image-bo(9790) | URL:http://www.iss.net/security_center/static/9790.php | BID:5409 | URL:http://www.securityfocus.com/bid/5409 | CALDERA:CSSA-2002-042.0 | URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-042.0.txt | Frech> XF:libpng-wide-image-bo(9790) | Christey> Change "Debian Linux" to "Debian GNU/Linux"  View
5089  CVE-2002-0699  Candidate  Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user"s system via HTML.  Modified (20061101)  ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(2) Foat, Frech | NOOP(2) Christey, Cox  Foat> Replace the word "Unknown" with "A" and change "allow" to "allows". | Christey> The "Unknown" portion of the vulnerability statement is used | to emphasize that the vendor has not provided sufficient | information to understand the cause or nature of the problem. | This is important because this vagueness makes it difficult | or impossible to resolve it with vulnerability reports | from other sources, increasing the risk of duplication. | | Most candidates affected by CD:VAGUE will use this description | style. | Christey> XF:win-certificate-enrollment-dos(9982) | URL:http://www.iss.net/security_center/static/9982.php | BID:5593 | URL:http://www.securityfocus.com/bid/5593 | Frech> XF:win-certificate-enrollment-dos(9982)  View

Page 1001 of 20943, showing 5 records out of 104715 total, starting on record 5001, ending on 5005

Actions