CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5266  CVE-2002-0876  Candidate  Web server for Shambala 4.5 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request.  Proposed (20020830)  ACCEPT(1) Frech | NOOP(6) Alderson, Armstrong, Cole, Cox, Foat, Jones    View
5267  CVE-2002-0877  Candidate  Directory traversal vulnerability in the FTP server for Shambala 4.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) LIST (ls) or (2) GET commands.  Proposed (20020830)  ACCEPT(1) Frech | NOOP(6) Alderson, Armstrong, Cole, Cox, Foat, Jones    View
5268  CVE-2002-0878  Candidate  SQL injection vulnerability in the login form for LogiSense software including (1) Hawk-i Billing, (2) Hawk-i ASP and (3) DNS Manager allows remote attackers to bypass authentication via SQL code in the password field.  Proposed (20020830)  ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall    View
5269  CVE-2002-0879  Candidate  showtemp.cfm for Gafware CFXImage 1.6.6 allows remote attackers to read arbitrary files via (1) a .. or (2) a C: style pathname in the FILE parameter.  Proposed (20020830)  ACCEPT(2) Alderson, Frech | MODIFY(1) Jones | NOOP(4) Armstrong, Cole, Cox, Foat  Jones> Suggest description adds "...CFXImage 1.6.6 and earlier does not | filter form input, allowing remote attackers to read...". Regarding | abstraction, vote not to SPLIT; agree that vulnerability is lack of input | filtering. SPLITting would imply that Cross-site scripting, etc. due to | same lack of form input filtering would require a new candidate, etc.  View
5270  CVE-2002-0880  Candidate  Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allow remote attackers to cause a denial of service (crash) via malformed packets as demonstrated by (1) "jolt", (2) "jolt2", (3) "raped", (4) "hping2", (5) "bloop", (6) "bubonic", (7) "mutant", (8) "trash", and (9) "trash2."  Proposed (20020830)  ACCEPT(3) Alderson, Cole, Foat | MODIFY(3) Baker, Frech, Jones | NOOP(2) Armstrong, Cox  Jones> Suggest description removes tool references: "Cisco IP Phone | (VoIP) models 7910, 7940, and 7960 allow remote | attackers to cause a denial of service (crash) via a flood of malformed IP | packets." The tools are just generators of specific malformed packets and | don"t actually represent vulnerabilities; the vulnerability is in the | ability of the Cisco device IP stack to handle various malformed packets. | Cisco description indicates that the solution was to improve the devices" | ability to handle high rates of traffic (not to repair specific packet | handling code in the stack). This suggests a single CVE entry (vice | multiple entries if the stack had a set of different vulnerabilities). | Baker> I agree the description should be changed to describe the problem as failure to handle malformed IP packets | Frech> XF:cisco-ipphone-multiple-dos(9145)  View

Page 1054 of 20943, showing 5 records out of 104715 total, starting on record 5266, ending on 5270

Actions