CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5041  CVE-2002-0651  Entry  Buffer overflow in the DNS resolver code used in libc, glibc, and libbind, as derived from ISC BIND, allows remote malicious DNS servers to cause a denial of service and possibly execute arbitrary code via the stub resolvers.        View
5042  CVE-2002-0652  Candidate  xfsmd for IRIX 6.5 through 6.5.16 allows remote attackers to execute arbitrary code via shell metacharacters that are not properly filtered from several calls to the popen() function, such as export_fs().  Proposed (20020726)  ACCEPT(1) Baker | NOOP(5) Christey, Cole, Cox, Foat, Wall  Christey> XF:irix-xfsmd-execute-commands(9402) | URL:http://www.iss.net/security_center/static/9402.php | BID:5075 | URL:http://www.securityfocus.com/bid/5075  View
5043  CVE-2002-0653  Entry  Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apache module 2.8.9 and earlier, allows local users to execute arbitrary code as the Apache server user via .htaccess files with long entries.        View
5044  CVE-2002-0654  Candidate  Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when a script (child process) cannot be invoked.  Modified (20071101)  ACCEPT(4) Armstrong, Baker, Cox, Foat | MODIFY(1) Frech | NOOP(1) Cole | REVIEWING(1) Wall  Frech> XF:apache-cgi-path-disclosure(9876) | XF:apache-var-path-disclosure(9875) | In description, correct product names to OS/2 and NetWare.  View
5045  CVE-2002-0655  Candidate  OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could allow attackers to cause a denial of service and possibly execute arbitrary code.  Proposed (20020830)  ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Cox | NOOP(2) Christey, Foat  Cox> ADDREF:RHSA-2002:163 RHSA-2002:164 RHSA-2002:157 | This issue also affects SSLeay and BSAFE SSL-C | ADDREF: http://www.rsasecurity.com/products/bsafe/bulletins/BSAFE_SSL_Products_Security_Bulletin_Aug_8_2002.pdf | Christey> CONFIRM:http://www.cisco.com/univercd/cc/td/doc/product/webscale/css/css_sca/sca_320/v320b20.htm#xtocid13 | Christey> I should probably create a separate CAN for the BSAFE issues, | unless there is a codebase relationship.  View

Page 1009 of 20943, showing 5 records out of 104715 total, starting on record 5041, ending on 5045

Actions