CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4395  CVE-2002-0001  Candidate  Vulnerability in RFC822 address parser in mutt before 1.2.5.1 and mutt 1.3.x before 1.3.25 allows remote attackers to execute arbitrary commands via an improperly terminated comment or phrase in the address list.  Modified (20050707)  ACCEPT(4) Baker, Cole, Green, Wall | MODIFY(1) Frech | NOOP(2) Christey, Foat  Christey> I need to review this for accuracy; is it just a buffer | overflow? See Mark Cox" comments in his "Chinese Whisper" | article. | Frech> XF:mutt-address-handling-bo(7759) | Christey> See Caldera advisory for a good, short description of the | issue. | BID:3774 | URL:http://www.securityfocus.com/bid/3774 | SUSE:SuSE-SA:2002:001 | URL:http://www.suse.de/de/support/security/2002_001_mutt_txt.html | CONECTIVA:CLA-2002:449 | DEBIAN:DSA-096 | FREEBSD:FreeBSD-SA-02:04 | HP:HPSBTL0201-011 | URL:http://online.securityfocus.com/advisories/3778 | CALDERA:CSSA-2002-002.0 | URL:http://www.calderasystems.com/support/security/advisories/CSSA-2002-002.0.txt  View
4442  CVE-2002-0048  Candidate  Multiple signedness errors (mixed signed and unsigned numbers) in the I/O functions of rsync 2.4.6, 2.3.2, and other versions allow remote attackers to cause a denial of service and execute arbitrary code in the rsync client or server.  Modified (20050510)  ACCEPT(4) Baker, Cole, Green, Wall | MODIFY(1) Frech | NOOP(2) Christey, Foat  Frech> XF:linux-rsync-root-access(7993) | Christey> CALDERA:CSSA-2002-003.0 | Christey> Consider adding BID:3958  View
4778  CVE-2002-0386  Candidate  The administration module for Oracle Web Cache in Oracle9iAS (9i Application Suite) 9.0.2 allows remote attackers to cause a denial of service (crash) via (1) an HTTP GET request containing a ".." (dot dot) sequence, or (2) a malformed HTTP GET request with a chunked Transfer-Encoding with missing data.  Modified (20050610)  ACCEPT(4) Baker, Cole, Green, Wall | NOOP(1) Cox    View
2967  CVE-2001-0146  Candidate  IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL"s.  Modified (20050509)  ACCEPT(4) Baker, Cole, Lawler, Ziese | NOOP(1) Christey | RECAST(1) Frech  Frech> (SF-EXEC) | XF:iis-malformed-url-dos(6171) | XF:exchange-malformed-url-dos(6172) | Not only is this two applications, but it is fixed by two patches. | Quoting Microsoft: | Because the flaw occurs in two different code modules, one of which installs | as part of IIS 5.0 and both of which install as part of Exchange 2000, it is | important for Exchange 2000 administrators to install both the IIS and | Exchange patches below. | Also, in the description, avoid using an apostrophe on "URLs" when it is | simply plural and not possessive (aka the "grocer"s apostrophe"). | Christey> Consider adding BID:2440 | Christey> Consider adding BID:2441  View
3041  CVE-2001-0220  Candidate  Buffer overflow in ja-elvis and ko-helvis ports of elvis allow local users to gain root privileges.  Proposed (20010309)  ACCEPT(4) Baker, Cole, Lawler, Ziese | RECAST(1) Frech  Frech> XF:ja-elvis-elvrec-bo(6074) | XF:ko-helvis-elvrec-bo(6075) | MODIFY/RECAST(SF-EXEC)  View

Page 1026 of 20943, showing 5 records out of 104715 total, starting on record 5126, ending on 5130

Actions