CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5760 | CVE-2002-1376 | Candidate | libmysqlclient client library in MySQL 3.x to 3.23.54, and 4.x to 4.0.6, does not properly verify length fields for certain responses in the (1) read_rows or (2) read_one_row routines, which allows remote attackers to cause a denial of service and possibly execute arbitrary code. | Modified (20071017) | ACCEPT(2) Cole, Green | MODIFY(1) Cox | Cox> Addref: REDHAT:RHSA-2002:289 | Green> ACKNOWLEDGED IN THE REDHAT ERRATA | View |
5759 | CVE-2002-1375 | Entry | The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary code via a long response. | View | |||
5758 | CVE-2002-1374 | Entry | The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, which causes MySQL to only compare the provided password against the first character of the real password. | View | |||
5757 | CVE-2002-1373 | Entry | Signed integer vulnerability in the COM_TABLE_DUMP package for MySQL 3.23.x before 3.23.54 allows remote attackers to cause a denial of service (crash or hang) in mysqld by causing large negative integers to be provided to a memcpy call. | View | |||
5756 | CVE-2002-1372 | Entry | Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values of various file and socket operations, which could allow a remote attacker to cause a denial of service (resource exhaustion) by causing file descriptors to be assigned and not released, as demonstrated by fanta. | View |
Page 19792 of 20943, showing 5 records out of 104715 total, starting on record 98956, ending on 98960