CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5760  CVE-2002-1376  Candidate  libmysqlclient client library in MySQL 3.x to 3.23.54, and 4.x to 4.0.6, does not properly verify length fields for certain responses in the (1) read_rows or (2) read_one_row routines, which allows remote attackers to cause a denial of service and possibly execute arbitrary code.  Modified (20071017)  ACCEPT(2) Cole, Green | MODIFY(1) Cox  Cox> Addref: REDHAT:RHSA-2002:289 | Green> ACKNOWLEDGED IN THE REDHAT ERRATA  View
5759  CVE-2002-1375  Entry  The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary code via a long response.        View
5758  CVE-2002-1374  Entry  The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, which causes MySQL to only compare the provided password against the first character of the real password.        View
5757  CVE-2002-1373  Entry  Signed integer vulnerability in the COM_TABLE_DUMP package for MySQL 3.23.x before 3.23.54 allows remote attackers to cause a denial of service (crash or hang) in mysqld by causing large negative integers to be provided to a memcpy call.        View
5756  CVE-2002-1372  Entry  Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values of various file and socket operations, which could allow a remote attacker to cause a denial of service (resource exhaustion) by causing file descriptors to be assigned and not released, as demonstrated by fanta.        View

Page 19792 of 20943, showing 5 records out of 104715 total, starting on record 98956, ending on 98960

Actions