CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4395 | CVE-2002-0001 | Candidate | Vulnerability in RFC822 address parser in mutt before 1.2.5.1 and mutt 1.3.x before 1.3.25 allows remote attackers to execute arbitrary commands via an improperly terminated comment or phrase in the address list. | Modified (20050707) | ACCEPT(4) Baker, Cole, Green, Wall | MODIFY(1) Frech | NOOP(2) Christey, Foat | Christey> I need to review this for accuracy; is it just a buffer | overflow? See Mark Cox" comments in his "Chinese Whisper" | article. | Frech> XF:mutt-address-handling-bo(7759) | Christey> See Caldera advisory for a good, short description of the | issue. | BID:3774 | URL:http://www.securityfocus.com/bid/3774 | SUSE:SuSE-SA:2002:001 | URL:http://www.suse.de/de/support/security/2002_001_mutt_txt.html | CONECTIVA:CLA-2002:449 | DEBIAN:DSA-096 | FREEBSD:FreeBSD-SA-02:04 | HP:HPSBTL0201-011 | URL:http://online.securityfocus.com/advisories/3778 | CALDERA:CSSA-2002-002.0 | URL:http://www.calderasystems.com/support/security/advisories/CSSA-2002-002.0.txt | View |
4442 | CVE-2002-0048 | Candidate | Multiple signedness errors (mixed signed and unsigned numbers) in the I/O functions of rsync 2.4.6, 2.3.2, and other versions allow remote attackers to cause a denial of service and execute arbitrary code in the rsync client or server. | Modified (20050510) | ACCEPT(4) Baker, Cole, Green, Wall | MODIFY(1) Frech | NOOP(2) Christey, Foat | Frech> XF:linux-rsync-root-access(7993) | Christey> CALDERA:CSSA-2002-003.0 | Christey> Consider adding BID:3958 | View |
4778 | CVE-2002-0386 | Candidate | The administration module for Oracle Web Cache in Oracle9iAS (9i Application Suite) 9.0.2 allows remote attackers to cause a denial of service (crash) via (1) an HTTP GET request containing a ".." (dot dot) sequence, or (2) a malformed HTTP GET request with a chunked Transfer-Encoding with missing data. | Modified (20050610) | ACCEPT(4) Baker, Cole, Green, Wall | NOOP(1) Cox | View | |
2967 | CVE-2001-0146 | Candidate | IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL"s. | Modified (20050509) | ACCEPT(4) Baker, Cole, Lawler, Ziese | NOOP(1) Christey | RECAST(1) Frech | Frech> (SF-EXEC) | XF:iis-malformed-url-dos(6171) | XF:exchange-malformed-url-dos(6172) | Not only is this two applications, but it is fixed by two patches. | Quoting Microsoft: | Because the flaw occurs in two different code modules, one of which installs | as part of IIS 5.0 and both of which install as part of Exchange 2000, it is | important for Exchange 2000 administrators to install both the IIS and | Exchange patches below. | Also, in the description, avoid using an apostrophe on "URLs" when it is | simply plural and not possessive (aka the "grocer"s apostrophe"). | Christey> Consider adding BID:2440 | Christey> Consider adding BID:2441 | View |
3041 | CVE-2001-0220 | Candidate | Buffer overflow in ja-elvis and ko-helvis ports of elvis allow local users to gain root privileges. | Proposed (20010309) | ACCEPT(4) Baker, Cole, Lawler, Ziese | RECAST(1) Frech | Frech> XF:ja-elvis-elvrec-bo(6074) | XF:ko-helvis-elvrec-bo(6075) | MODIFY/RECAST(SF-EXEC) | View |
Page 1026 of 20943, showing 5 records out of 104715 total, starting on record 5126, ending on 5130