CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5870 | CVE-2002-1486 | Candidate | Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service and possibly execute arbitrary code via (1) a large response from the server, (2) a JOIN with a long channel name, (3) a long "raw 221" message, (4) a PRIVMSG with a long nickname, or (5) a long response from an IDENT server. | Proposed (20030317) | ACCEPT(3) Armstrong, Baker, Cole | NOOP(3) Christey, Cox, Wall | Christey> XF:trillian-irc-privmsg-bo(10143) | URL:http://www.iss.net/security_center/static/10143.php | BID:5755 | URL:http://www.securityfocus.com/bid/5755 | View |
5869 | CVE-2002-1485 | Candidate | The AIM component of Trillian 0.73 and 0.74 allows remote attackers to cause a denial of service (crash) via certain strings such as "P > O < C". | Modified (20050602) | NOOP(5) Armstrong, Baker, Cole, Cox, Wall | View | |
5868 | CVE-2002-1484 | Candidate | DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a connection status in the resulting error message. | Proposed (20030317) | ACCEPT(2) Armstrong, Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall | Baker> The default behavior is the verbose debug messages, so the description should indicate that this is the default configuration. | View |
5867 | CVE-2002-1483 | Candidate | db4web_c and db4web_c.exe programs in DB4Web 3.4 and 3.6 allow remote attackers to read arbitrary files via an HTTP request whose argument is a filename of the form (1) C: (drive letter), (2) //absolute/path (double-slash), or (3) .. (dot-dot). | Proposed (20030317) | ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall | View | |
5866 | CVE-2002-1482 | Candidate | SQL injection vulnerability in login.php for phpGB 1.20 and earlier, when magic_quotes_gpc is not enabled, allows remote attackers to gain administrative privileges via SQL code in the password entry. | Proposed (20030317) | ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall | View |
Page 19770 of 20943, showing 5 records out of 104715 total, starting on record 98846, ending on 98850