CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2780  CVE-2000-1213  Candidate  ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, does not drop privileges after acquiring a raw socket, which increases ping"s exposure to bugs that otherwise would occur at lower privileges.  Proposed (20020830)  ACCEPT(7) Armstrong, Baker, Cole, Cox, Foat, Green, Wall | MODIFY(1) Frech  Frech> XF:iputils-ping-privileges(11090)  View
3326  CVE-2001-0509  Candidate  Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.  Modified (20061101)  ACCEPT(7) Armstrong, Baker, Bishop, Cole, Foat, Wall, Ziese | MODIFY(1) Frech | NOOP(1) Christey  Frech> XF:ms-malformed-rpc-dos(6914) | Christey> BID:3104 | URL:http://www.securityfocus.com/bid/3104 | BUGTRAQ:20010730 Multiple Remote DoS vulnerabilities in Microsoft DCE/RPC deamons | URL:http://online.securityfocus.com/archive/1/200450  View
4406  CVE-2002-0012  Candidate  Vulnerabilities in a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via SNMPv1 trap handling, as demonstrated by the PROTOS c06-SNMPv1 test suite. NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor. This and other SNMP-related candidates will be updated when more accurate information is available.  Modified (20061101)  ACCEPT(6) Cole, Foat, Green, Jones, Wall, Ziese | REVIEWING(1) Christey  Christey> This candidate is at a higher level of abstraction (more | general) than most other candidates. CVE"s content | decisions suggest that we should provide different candidates | for each implementation and type of bug that is affected by | the PROTOS suite. | | However, as of this writing (Feb 12, 2002), there is | insufficient information to assign the proper number of | candidates. This high-level candidate will serve as a | "catch-all," but we will be assigning lower-level (more | specific) candidates when there is more information. | | Due to the size and extent of this problem, it is better to | have a high-level candidate than no candidate at all. | Ziese> ACKNOWLEDGED-BY-VENDOR | Christey> DEBIAN:DSA-111 | MANDRAKE:MDKSA-2002:014 | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> CALDERA:CSSA-2002-004.0 | Christey> Consider adding BID:4088 | Christey> ADDREF SGI:20020404-01-P, which discusses the "hpsnmpd" daemon. | Christey> COMPAQ:SSRT0799 | CONECTIVA:CLA-2002:462 | BID:4088 | DEBIAN:DSA-111 | HP:HPSBUX0202-184 | URL:http://online.securityfocus.com/advisories/4032 | CISCO:20020212 Malformed SNMP Message-Handling Vulnerabilities | CISCO:20020212 Malformed SNMP Message-Handling Vulnerabilities for Cisco Non-IOS Products | MANDRAKE:MDKSA-2002:014 | FREEBSD:FreeBSD-SA-02:11 | Christey> SUSE:SuSE-SA:2002:012 | | Should also mention ucd-snmp package by name. | BUGTRAQ:20020824 NOVL-2002-2961546 - SNMPv1 Trap and Request Handling Vulnerabilities | URL:http://archives.neohapsis.com/archives/bugtraq/2002-08/0295.html | HP:HPSBMP0206-015 | URL:http://archives.neohapsis.com/archives/hp/2002-q4/0010.html | CALDERA:CSSA-2002-SCO.25 | URL:http://archives.neohapsis.com/archives/linux/caldera/2002-q2/0024.html | CALDERA:CSSA-2002-004.1 | URL:ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2002-004.1 | BUGTRAQ:20020227 nCipher Security Advisory #2: SNMP vulnerabilities | URL:http://archives.neohapsis.com/archives/bugtraq/2002-02/0353.html | Christey> REDHAT:RHSA-2002:036 | URL:http://www.redhat.com/support/errata/RHSA-2002-036.html  View
4407  CVE-2002-0013  Candidate  Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via (1) GetRequest, (2) GetNextRequest, and (3) SetRequest messages, as demonstrated by the PROTOS c06-SNMPv1 test suite. NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor. This and other SNMP-related candidates will be updated when more accurate information is available.  Modified (20061101)  ACCEPT(6) Cole, Foat, Green, Jones, Wall, Ziese | REVIEWING(1) Christey  Christey> This candidate is at a higher level of abstraction (more | general) than most other candidates. CVE"s content | decisions suggest that we should provide different candidates | for each implementation and type of bug that is affected by | the PROTOS suite. | | However, as of this writing (Feb 12, 2002), there is | insufficient information to assign the proper number of | candidates. This high-level candidate will serve as a | "catch-all," but we will be assigning lower-level (more | specific) candidates when there is more information. | | Due to the size and extent of this problem, it is better to | have a high-level candidate than no candidate at all. | Christey> BID:4089 | Christey> DEBIAN:DSA-111 | MANDRAKE:MDKSA-2002:014 | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> CALDERA:CSSA-2002-004.0 | Christey> ADDREF SGI:20020404-01-P, which discusses the "hpsnmpd" daemon. | Christey> COMPAQ:SSRT0799 | CONECTIVA:CLA-2002:462 | DEBIAN:DSA-111 | HP:HPSBUX0202-184 | URL:http://online.securityfocus.com/advisories/4032 | CISCO:20020212 Malformed SNMP Message-Handling Vulnerabilities | CISCO:20020212 Malformed SNMP Message-Handling Vulnerabilities for Cisco Non-IOS Products | MANDRAKE:MDKSA-2002:014 | FREEBSD:FreeBSD-SA-02:11 | Christey> SUSE:SuSE-SA:2002:012 | | Should also mention ucd-snmp package by name. | BUGTRAQ:20020824 NOVL-2002-2961546 - SNMPv1 Trap and Request Handling Vulnerabilities | URL:http://archives.neohapsis.com/archives/bugtraq/2002-08/0295.html | HP:HPSBMP0206-015 | URL:http://archives.neohapsis.com/archives/hp/2002-q4/0010.html | CALDERA:CSSA-2002-SCO.25 | URL:http://archives.neohapsis.com/archives/linux/caldera/2002-q2/0024.html | CALDERA:CSSA-2002-004.1 | URL:ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2002-004.1 | BUGTRAQ:20020227 nCipher Security Advisory #2: SNMP vulnerabilities | URL:http://archives.neohapsis.com/archives/bugtraq/2002-02/0353.html | Christey> SUNALERT:57404 | Christey> REDHAT:RHSA-2002:036 | URL:http://www.redhat.com/support/errata/RHSA-2002-036.html  View
4020  CVE-2001-1216  Candidate  Buffer overflow in PL/SQL Apache module in Oracle 9i Application Server allows remote attackers to execute arbitrary code via a long request for a help page.  Proposed (20020315)  ACCEPT(6) Cole, Foat, Frech, Green, Wall, Ziese | NOOP(1) Christey  Christey> CERT:CA-2002-08  View

Page 19853 of 20943, showing 5 records out of 104715 total, starting on record 99261, ending on 99265

Actions