CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5825 | CVE-2002-1441 | Candidate | Multiple buffer overflows in Tomahawk SteelArrow before 4.5 allow remote attackers to execute arbitrary code via (1) the Steelarrow Service (Steelarrow.exe) using a long UserIdent Cookie header, (2) DLLHOST.EXE (Steelarrow.dll) via a request for a long .aro file, or (3) DLLHOST.EXE via a Chunked Transfer-Encoding request. | Proposed (20030317) | ACCEPT(1) Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall | Baker> THere is no changelog file in the installer either, so it is difficult to determine how many issues were addressed in the new version. | View |
5824 | CVE-2002-1440 | Candidate | The Gateway GS-400 server has a default root password of "0001n" that can not be changed via the administrative interface, which can allow attackers to gain root privileges. | Proposed (20030317) | ACCEPT(1) Cole | NOOP(2) Cox, Wall | View | |
5823 | CVE-2002-1439 | Candidate | Unknown vulnerability related to stack corruption in the TGA daemon for HP-UX 11.04 (VVOS) Virtualvault 4.0, 4.5, and 4.6 may allow attackers to obtain access to system files. | Proposed (20030317) | ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox | View | |
5822 | CVE-2002-1438 | Entry | The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to obtain Perl version information via the -v option. | View | |||
5821 | CVE-2002-1437 | Entry | Directory traversal vulnerability in the web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to read arbitrary files via an HTTP request containing "..%5c" (URL-encoded dot-dot backslash) sequences. | View |
Page 19779 of 20943, showing 5 records out of 104715 total, starting on record 98891, ending on 98895