CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3882  CVE-2001-1078  Candidate  Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format specifiers in the SMTP commands (1) HELO, (2) EHLO, (3) MAIL FROM, or (4) RCPT TO, and the POP3 commands (5) USER and (6) other commands that can be executed after POP3 authentication.  Proposed (20020131)  ACCEPT(5) Armstrong, Baker, Cole, Frech, Green | NOOP(2) Foat, Wall    View
5251  CVE-2002-0861  Candidate  Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to bypass the "Allow paste operations via script" setting, even when it is disabled, via the (1) Copy method of the Cell object or (2) the Paste method of the Range object.  Proposed (20020830)  ACCEPT(5) Armstrong, Baker, Cole, Frech, Wall | NOOP(2) Cox, Foat    View
3845  CVE-2001-1041  Candidate  oracle program in Oracle 8.0.x, 8.1.x and 9.0.1 allows local users to overwrite arbitrary files via a symlink attack on an Oracle log trace (.trc) file that is created in an alternate home directory identified by the ORACLE_HOME environment variable.  Proposed (20020131)  ACCEPT(5) Armstrong, Baker, Cole, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat | REVIEWING(1) Christey  Frech> XF:oracle-binary-symlink(6940) | Possible overlap with CVE-2001-0832 (overlapping | references)? | Christey> Possible dupe with CVE-2001-0832; need to review more closely. | CHANGE> [Christey changed vote from NOOP to REVIEWING]  View
2776  CVE-2000-1209  Candidate  The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida.  Modified (20071113)  ACCEPT(5) Armstrong, Baker, Cole, Green, Wall | MODIFY(1) Frech | NOOP(3) Christey, Cox, Foat  Frech> XF:tumbleweed-mms-blank-password(5072) | XF:msde-mssql-default-password(9154) | May overlap with CVE-2000-0772. | Christey> fix desc - "installed with a default password" appears twice.  View
8482  CVE-2004-0054  Candidate  Multiple vulnerabilities in the H.323 protocol implementation for Cisco IOS 11.3T through 12.2T allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.  Modified (20090302)  ACCEPT(5) Armstrong, Baker, Cole, Green, Wall | NOOP(1) Cox    View

Page 1061 of 20943, showing 5 records out of 104715 total, starting on record 5301, ending on 5305

Actions