CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5156  CVE-2002-0766  Entry  OpenBSD 2.9 through 3.1 allows local users to cause a denial of service (resource exhaustion) and gain root privileges by filling the kernel"s file descriptor table and closing file descriptors 0, 1, or 2 before executing a privileged process, which is not properly handled when OpenBSD fails to open an alternate descriptor.        View
5157  CVE-2002-0767  Candidate  simpleinit on Linux systems does not close a read/write FIFO file descriptor before creating a child process, which allows the child process to cause simpleinit to execute arbitrary programs with root privileges.  Proposed (20020726)  NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
5158  CVE-2002-0768  Entry  Buffer overflow in lukemftp FTP client in SuSE 6.4 through 8.0, and possibly other operating systems, allows a malicious FTP server to execute arbitrary code via a long PASV command.        View
5159  CVE-2002-0769  Candidate  The web-based configuration interface for the Cisco ATA 186 Analog Telephone Adaptor allows remote attackers to bypass authentication via an HTTP POST request with a single byte, which allows the attackers to (1) obtain the password from the login screen, or (2) reconfigure the adaptor by modifying certain request parameters.  Proposed (20020726)  ACCEPT(3) Armstrong, Baker, Cole | NOOP(3) Cox, Foat, Wall    View
5160  CVE-2002-0770  Candidate  Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute Q2 server admin commands via a client that does not expand "$" macros, which causes the server to expand the macros and leak the information, as demonstrated using "say $rcon_password."  Modified (20051128)  NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View

Page 1032 of 20943, showing 5 records out of 104715 total, starting on record 5156, ending on 5160

Actions