CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6252  CVE-2002-1870  Candidate  Simple Web Server (SWS) 0.0.4 through 0.1.0 does not properly handle when the recv function call fails, which may allow remote attackers to overwrite program data or perform actions on an uninitialized heap, leading to a denial of service and possibly code execution.  Assigned (20050629)  None (candidate not yet proposed)    View
6253  CVE-2002-1871  Candidate  pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a "?" (question mark) in the (1) mode, (2) owner, or (3) group fields, which allows attackers to elevate privileges.  Assigned (20050629)  None (candidate not yet proposed)    View
6254  CVE-2002-1872  Candidate  Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password.  Assigned (20050629)  None (candidate not yet proposed)    View
6255  CVE-2002-1873  Candidate  Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attackers to cause a denial of service (crash or memory consumption) via malformed MSRPC calls.  Assigned (20050629)  None (candidate not yet proposed)    View
6256  CVE-2002-1874  Candidate  astrocam.cgi in AstroCam 0.9-1-1 through 1.4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request. NOTE: earlier disclosures stated that the affected versions were 1.7.1 through 2.1.2, but the vendor explicitly stated that these were incorrect.  Assigned (20050629)  None (candidate not yet proposed)    View

Page 1727 of 20943, showing 5 records out of 104715 total, starting on record 8631, ending on 8635

Actions