CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6927  CVE-2003-0098  Candidate  Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server.  Modified (20071016)  ACCEPT(4) Armstrong, Cole, Green, Jones | NOOP(2) Christey, Cox  Christey> SUSE:SuSE-SA:2003:022 | CALDERA:CSSA-2003-015.0 | Christey> DEBIAN:DSA-277 | URL:http://www.debian.org/security/2003/dsa-277 | Christey> CHANGEREF BID:6828 | (BID:7200 is for the overflows)  View
6928  CVE-2003-0099  Candidate  Multiple buffer overflows in apcupsd before 3.8.6, and 3.10.x before 3.10.5, may allow attackers to cause a denial of service or execute arbitrary code, related to usage of the vsprintf function.  Modified (20071016)  ACCEPT(4) Armstrong, Cole, Green, Jones | NOOP(2) Christey, Cox  Christey> SUSE:SuSE-SA:2003:022 | CALDERA:CSSA-2003-015.0 | Christey> DEBIAN:DSA-277 | URL:http://www.debian.org/security/2003/dsa-277 | Christey> As observed in an email to us by a third party, it appears | that 3.8.6 is probably not affected by this, so the | description should be changed to refer to "3.10.x before | 3.10.5, and 3.8.x before 3.8.6". | Christey> An email from Kern Sibbald on August 21, 2003, confirmed that | 3.8.6 and 3.10.5 fixed the issue. | | CONFIRM:http://sourceforge.net/project/shownotes.php?release_id=137892  View
6930  CVE-2003-0101  Candidate  miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote attackers to spoof a session ID and gain root privileges.  Modified (20080207)  ACCEPT(4) Armstrong, Cole, Green, Jones | NOOP(2) Christey, Cox  Christey> SGI:20030602-01-I | The "websetup v 3.5 package from IRIX 6.5.20 Applications CD" | uses Webmin; may wish to add this name to the description. | Christey> DEBIAN:DSA-319 | Christey> CIAC:N-058 | URL:http://www.ciac.org/ciac/bulletins/n-058.shtml | ENGARDE:ESA-20030225-006 | URL:http://archives.neohapsis.com/archives/linux/engarde/2003-q1/0008.html | HP:HPSBUX0303-250 | URL:http://archives.neohapsis.com/archives/hp/2003-q1/0063.html | BID:6915 | URL:http://www.securityfocus.com/bid/6915  View
6973  CVE-2003-0144  Candidate  Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) user name.  Modified (20071113)  ACCEPT(4) Armstrong, Cole, Green, Jones | NOOP(2) Christey, Cox  Christey> DEBIAN:DSA-267 | URL:http://www.debian.org/security/2003/dsa-267 | Christey> DEBIAN:DSA-275 | URL:http://www.debian.org/security/2003/dsa-275 | Christey> DEBIAN:DSA-267 | URL:http://www.debian.org/security/2003/dsa-267 | Christey> SGI:20030406-02-P | Christey> MANDRAKE:MDKSA-2003:059 | URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:059  View
6885  CVE-2003-0056  Candidate  Buffer overflow in secure locate (slocate) before 2.7 allows local users to execute arbitrary code via a long (1) -c or (2) -r command line argument.  Modified (20100819)  ACCEPT(4) Armstrong, Cole, Green, Jones | NOOP(2) Christey, Cox  Christey> REDHAT:RHSA-2004:041 | URL:http://www.redhat.com/support/errata/RHSA-2004-041.html | Christey> SGI:20040201-01-U  View

Page 1011 of 20943, showing 5 records out of 104715 total, starting on record 5051, ending on 5055

Actions