CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
475 | CVE-1999-0477 | Candidate | The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly. | Modified (19991210-01) | ACCEPT(4) Baker, Christey, Frech, Ozancin | REJECT(1) Wall | Wall> Duplicate of 0455 | Christey> CVE-1999-0477 and CVE-1999-0455 were discovered at different | times. Also, the attack was different. So "Same Attack" and | "Same Time of Discovery" dictate that these should remain | separate. | View |
2426 | CVE-2000-0857 | Candidate | The logging capability in muh 2.05d IRC server does not properly cleanse user-injected format strings, which allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed nickname. | Proposed (20001018) | ACCEPT(4) Baker, Cole, Collins, Frech | NOOP(4) Armstrong, Christey, Magdych, Wall | Cole> HAS-INDEPENDENT-CONFIRMATION | Christey> ADDREF FREEBSD:FreeBSD-SA-00:57 | CHANGE> [Magdych changed vote from REVIEWING to NOOP] | View |
2589 | CVE-2000-1020 | Candidate | Heap overflow in Worldclient in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long URL. | Proposed (20001129) | ACCEPT(4) Baker, Cole, Collins, Mell | NOOP(1) Wall | View | |
2590 | CVE-2000-1021 | Candidate | Heap overflow in WebConfig in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long URL. | Proposed (20001129) | ACCEPT(4) Baker, Cole, Collins, Mell | NOOP(1) Wall | View | |
5215 | CVE-2002-0825 | Candidate | Buffer overflow in the DNS SRV code for nss_ldap before nss_ldap-198 allows remote attackers to cause a denial of service and possibly execute arbitrary code. | Proposed (20020830) | ACCEPT(4) Baker, Cole, Cox, Foat | NOOP(2) Christey, Wall | Christey> REDHAT:RHSA-2002:084 | Christey> REDHAT:RHSA-2002:084 | Christey> BUGTRAQ:20021013 GLSA: nss_ldap | | Need to determine if the nss_ldap-199 "read buffer overflow" | (basically an incomplete patch to this issue) should get | a different CAN. | Christey> MANDRAKE:MDKSA-2002:075 | Christey> CALDERA:CSSA-2002-058.0 | Christey> XF:nssldap-dns-query-dos(10578) | URL:http://www.iss.net/security_center/static/10578.php | BID:6130 | URL:http://www.securityfocus.com/bid/6130 | Christey> The Red Hat advisory suggests this is a format string issue, | not a buffer overflow. Also may need to mention the | pam_ldap module. | Christey> REDHAT:RHSA-2002:175 | View |
Page 1015 of 20943, showing 5 records out of 104715 total, starting on record 5071, ending on 5075