CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4664 | CVE-2002-0272 | Candidate | Buffer overflows in mpg321 before 0.2.9 allows local and possibly remote attackers to execute arbitrary code via a long URL to (1) a command line option, (2) an HTTP request, or (3) an FTP request. | Proposed (20020502) | ACCEPT(2) Armstrong, Cole | MODIFY(2) Cox, Frech | NOOP(3) Christey, Foat, Wall | Cox> "possibly" is vague. It can be exploited by remote attackers | if doing network streaming. | Christey> REDHAT:RHSA-2002:078 | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:mpg321-long-filename-bo(10032) | View |
4672 | CVE-2002-0280 | Candidate | Buffer overflow in CodeBlue 4 and earlier, and possibly other versions, allows remote attackers to execute arbitrary code via a long string in an SMTP reply. | Proposed (20020502) | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | Frech> May have been "rediscovered" by VulnWatch Mailing List, Wed | Jul 24 2002 - 11:05:00 CDT, "Remote hole in Codeblue log scanner" at | http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0037.html. | If these are the same issue, then v5 also contains this security | issue. | View |
4675 | CVE-2002-0283 | Candidate | Windows XP with port 445 open allows remote attackers to cause a denial of service (CPU consumption) via a flood of TCP SYN packets containing possibly malformed data. | Proposed (20020502) | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Cox, Foat | REVIEWING(1) Wall | Frech> XF:winxp-cifs-dos(8209) | View |
4676 | CVE-2002-0284 | Candidate | Winamp 2.78 and 2.77, when opening a wma file that requires a license, sends the full path of the Temporary Internet Files directory to the web page that is processing the license, which could allow malicious web servers to obtain the pathname. | Proposed (20020502) | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:winamp-wma-pathname-disclosure(10030) | View |
4680 | CVE-2002-0288 | Candidate | Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (triple dot dot) in the HTTP request. | Proposed (20020502) | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | Frech> XF:phusion-dot-directoy-traversal(8212) | View |
Page 133 of 20943, showing 5 records out of 104715 total, starting on record 661, ending on 665