CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6252 | CVE-2002-1870 | Candidate | Simple Web Server (SWS) 0.0.4 through 0.1.0 does not properly handle when the recv function call fails, which may allow remote attackers to overwrite program data or perform actions on an uninitialized heap, leading to a denial of service and possibly code execution. | Assigned (20050629) | None (candidate not yet proposed) | View | |
6253 | CVE-2002-1871 | Candidate | pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a "?" (question mark) in the (1) mode, (2) owner, or (3) group fields, which allows attackers to elevate privileges. | Assigned (20050629) | None (candidate not yet proposed) | View | |
6254 | CVE-2002-1872 | Candidate | Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password. | Assigned (20050629) | None (candidate not yet proposed) | View | |
6255 | CVE-2002-1873 | Candidate | Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attackers to cause a denial of service (crash or memory consumption) via malformed MSRPC calls. | Assigned (20050629) | None (candidate not yet proposed) | View | |
6256 | CVE-2002-1874 | Candidate | astrocam.cgi in AstroCam 0.9-1-1 through 1.4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request. NOTE: earlier disclosures stated that the affected versions were 1.7.1 through 2.1.2, but the vendor explicitly stated that these were incorrect. | Assigned (20050629) | None (candidate not yet proposed) | View |
Page 1727 of 20943, showing 5 records out of 104715 total, starting on record 8631, ending on 8635