CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3579  CVE-2001-0772  Candidate  Buffer overflows and other vulnerabilities in multiple Common Desktop Environment (CDE) modules in HP-UX 10.10 through 11.11 allow attackers to cause a denial of service and possibly gain additional privileges.  Modified (20090302)  ACCEPT(4) Baker, Cole, Foat, Frech | NOOP(2) Armstrong, Wall | REVIEWING(1) Christey  Christey> There is some overlap between CVE-2001-0551 and CVE-2001-0772. | CVE-2001-0551 describes a specific vulnerability in | dtprintinfo. HP acknowledges CVE-2001-0551 by stating | that the problem is fixed in HP:HPSBUX0105-151, which | is CVE-2001-0772. But CVE-2001-0772 is a vague advisory | that identifies other vulnerabilities (and vulnerability | types) besides CVE-2001-0551. Perhaps CVE-2001-0772 should | be RECAST to "remove" the reference to dtprintinfo and | leave the other vague descriptions. CVE-2001-0772 and | CVE-2001-0551 are very good examples of the problems that | CVE faces in being consistent with respect to the level of | abstraction, as documented in the CD:SF-CODEBASE, CD:SF-LOC, | and CD:VAGUE content decisions.  View
2764  CVE-2000-1197  Candidate  POP2 or POP3 server (pop3d) in imap-uw IMAP package on FreeBSD and other operating systems creates lock files with predictable names, which allows local users to cause a denial of service (lack of mail access) for other users by creating lock files for other mail boxes.  Proposed (20010912)  ACCEPT(4) Baker, Cole, Foat, Stracener | MODIFY(1) Frech | NOOP(1) Wall  Foat> ACKNOWLEDGED-BY-VENDOR | Frech> XF:freebsd-imap-uw(4335) | Frech> Please change XF:freebsd-imap-uw(4335) to XF:pop-predictable-lockfile(4335)  View
5039  CVE-2002-0649  Candidate  Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption, as exploited by the Slammer/Sapphire worm.  Modified (20080207)  ACCEPT(4) Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(2) Christey, Cox  Christey> CERT:CA-2002-22 | CERT-VN:VU#399260 | CERT-VN:VU#484891 | Christey> XF:mssql-resolution-service-bo(9661) | URL:http://www.iss.net/security_center/static/9661.php | BID:5310 | URL:http://www.securityfocus.com/bid/5310 | BID:5311 | URL:http://www.securityfocus.com/bid/5311 | Christey> add to desc: "as exploited by the SQL Slammer/Sapphire worm" | to facilitate matching. | Frech> XF:mssql-resolution-service-bo(9661)  View
5187  CVE-2002-0797  Candidate  Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.  Modified (20061101)  ACCEPT(4) Baker, Cole, Foat, Wall | NOOP(1) Cox    View
5186  CVE-2002-0796  Candidate  Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges.  Modified (20061101)  ACCEPT(4) Baker, Cole, Foat, Wall | NOOP(2) Christey, Cox  Christey> CIAC:M-086 | URL:http://www.ciac.org/ciac/bulletins/m-086.shtml  View

Page 1017 of 20943, showing 5 records out of 104715 total, starting on record 5081, ending on 5085

Actions