CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5360  CVE-2002-0972  Candidate  Buffer overflows in PostgreSQL 7.2 allow attackers to cause a denial of service and possibly execute arbitrary code via long arguments to the functions (1) lpad or (2) rpad.  Modified (20071113)  MODIFY(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall  Christey> SUSE:SuSE-SA:2002:039 | Christey> There are numerous PostgreSQL issues that were reported around | the same time frame. Need to make sure that they are all | properly identified. | Christey> CONFIRM:http://marc.theaimsgroup.com/?l=postgresql-announce&m=103062536330644 | CONFIRM:http://archives.postgresql.org/pgsql-announce/2002-08/msg00004.php | CONECTIVA:CLA-2002:524 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000524 | SUSE:SuSE-SA:2002:038 | URL:http://www.suse.de/de/security/2002_038_postgresql.html | BUGTRAQ:20020826 GLSA: PostgreSQL | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=103036987114437&w=2 | BUGTRAQ:20020824 Fwd: [GENERAL] PostgreSQL 7.2.2: Security Release | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=103021186622725&w=2 | Christey> MANDRAKE:MDKSA-2002:062 | URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2002:062 | REDHAT:RHSA-2003:015 | URL:http://www.redhat.com/support/errata/RHSA-2003-015.html | Frech> XF:postgresql-lpad-rpad-bo(9927) | Christey> REDHAT:RHSA-2003:010  View
5359  CVE-2002-0971  Candidate  Vulnerability in VNC, TightVNC, and TridiaVNC allows local users to execute arbitrary code as LocalSystem by using the Win32 Messaging System to bypass the VNC GUI and access the "Add new clients" dialogue box.  Modified (20050610)  MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Cox, Foat | REVIEWING(1) Wall  Frech> XF:vnc-win32-messaging-privileges(9979)  View
5358  CVE-2002-0970  Entry  The SSL capability for Konqueror in KDE 3.0.2 and earlier does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack.        View
5357  CVE-2002-0969  Entry  Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini initialization file, whose permissions on Windows allow Full Control to the Everyone group.        View
5356  CVE-2002-0968  Entry  Buffer overflow in AnalogX SimpleServer:WWW 1.16 and earlier allows remote attackers to cause a denial of service (crash) and execute code via a long HTTP request method name.        View

Page 19872 of 20943, showing 5 records out of 104715 total, starting on record 99356, ending on 99360

Actions