CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5825  CVE-2002-1441  Candidate  Multiple buffer overflows in Tomahawk SteelArrow before 4.5 allow remote attackers to execute arbitrary code via (1) the Steelarrow Service (Steelarrow.exe) using a long UserIdent Cookie header, (2) DLLHOST.EXE (Steelarrow.dll) via a request for a long .aro file, or (3) DLLHOST.EXE via a Chunked Transfer-Encoding request.  Proposed (20030317)  ACCEPT(1) Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall  Baker> THere is no changelog file in the installer either, so it is difficult to determine how many issues were addressed in the new version.  View
5824  CVE-2002-1440  Candidate  The Gateway GS-400 server has a default root password of "0001n" that can not be changed via the administrative interface, which can allow attackers to gain root privileges.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall    View
5823  CVE-2002-1439  Candidate  Unknown vulnerability related to stack corruption in the TGA daemon for HP-UX 11.04 (VVOS) Virtualvault 4.0, 4.5, and 4.6 may allow attackers to obtain access to system files.  Proposed (20030317)  ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox    View
5822  CVE-2002-1438  Entry  The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to obtain Perl version information via the -v option.        View
5821  CVE-2002-1437  Entry  Directory traversal vulnerability in the web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to read arbitrary files via an HTTP request containing "..%5c" (URL-encoded dot-dot backslash) sequences.        View

Page 19779 of 20943, showing 5 records out of 104715 total, starting on record 98891, ending on 98895

Actions