CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4869  CVE-2002-0477  Candidate  Standalone Macromedia Flash Player 5.0 before 5,0,30,2 allows remote attackers to execute arbitrary programs via a .SWF file containing the "exec" FSCommand.  Proposed (20020611)  ACCEPT(5) Baker, Cole, Frech, Green, Wall | NOOP(2) Cox, Foat | REVIEWING(1) Christey  Christey> Is swf_clear.html *really* related to standalone_update.htm? | Or is the former really talking about a third issue related to | a virus? standalone_update.htm is clearly fscommand ("exec"). | It has an "Additional information" statement that says: | "For a description of the potential issue with the previous | stand-alone player, please refer to [swf_clear.htm]" | | I interpret "the previous stand-alone player" as meaning "the player | that we are updating with this advisory." Since we know that | standalone_update.htm is exec, this implies that swf_clear.htm is | really the exec issue. However, swf_clear.html doesn"t | mention fscommand ("exec") AT ALL, which casts doubt or at | least uncertainty as to my conclusions. | | swf_clear.html links back to standalone_update.htm, so at | least the references are circular. | | At least it"s pretty clear that this issue is different from | CVE-2002-0476. | | Email inquiry sent to Macromedia on June 13, 2002.  View
5345  CVE-2002-0957  Candidate  The default configuration of BlackICE Agent 3.1.eal and 3.1.ebh has a high tcp.maxconnections setting, which could allow remote attackers to cause a denial of service (memory consumption) via a large number of connections to the BlackICE system that consumes more resources than intended by the user.  Proposed (20020830)  ACCEPT(5) Baker, Cole, Frech, Green, Wall | NOOP(2) Cox, Foat    View
3355  CVE-2001-0542  Candidate  Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf. NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CVE-2001-0879.  Modified (20061101)  ACCEPT(5) Baker, Cole, Frech, Green, Wall | NOOP(1) Foat    View
5074  CVE-2002-0684  Candidate  Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by functions such as getnetbyname and getnetbyaddr.  Modified (20040818)  ACCEPT(5) Baker, Cole, Foat, Green, Wall | MODIFY(2) Cox, Frech | NOOP(1) Christey  Cox> RHSA-2002:133 is CVE-2002-0651 not this one, ADDREF:RHSA-2002:167 | Christey> HP:HPSBUX0209-218 | URL:http://archives.neohapsis.com/archives/hp/2002-q3/0087.html | Frech> XF:dns-resolver-lib-bo(9432) | Christey> DELREF REDHAT:RHSA-2002:133 | Christey> DELREF REDHAT:RHSA-2002:133  View
3070  CVE-2001-0249  Candidate  Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.  Interim (20010911)  ACCEPT(5) Baker, Cole, Dik, Renaud, Ziese | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:ftp-glob-expansion(6332) | Dik> sun bug: 4436988 | Dik> sun bug: 4436988  View

Page 19876 of 20943, showing 5 records out of 104715 total, starting on record 99376, ending on 99380

Actions