CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3869  CVE-2001-1065  Candidate  Web-based configuration utility in Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap binds itself to port 80 even when web-based configuration services are disabled, which could leave the router open to attack.  Proposed (20020131)  ACCEPT(5) Armstrong, Baker, Cole, Frech, Green | NOOP(2) Foat, Wall    View
3881  CVE-2001-1077  Candidate  Buffer overflow in tt_printf function of rxvt 2.6.2 allows local users to gain privileges via a long (1) -T or (2) -name argument.  Proposed (20020131)  ACCEPT(5) Armstrong, Baker, Cole, Frech, Green | NOOP(2) Foat, Wall    View
3882  CVE-2001-1078  Candidate  Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format specifiers in the SMTP commands (1) HELO, (2) EHLO, (3) MAIL FROM, or (4) RCPT TO, and the POP3 commands (5) USER and (6) other commands that can be executed after POP3 authentication.  Proposed (20020131)  ACCEPT(5) Armstrong, Baker, Cole, Frech, Green | NOOP(2) Foat, Wall    View
5242  CVE-2002-0852  Candidate  Buffer overflows in Cisco Virtual Private Network (VPN) Client 3.5.4 and earlier allows remote attackers to cause a denial of service via (1) an Internet Key Exchange (IKE) with a large Security Parameter Index (SPI) payload, or (2) an IKE packet with a large number of valid payloads.  Proposed (20020830)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(2) Christey, Cox  Christey> "allows" should be "allow" | Christey> CERT-VN:VU#287771 | URL:http://www.kb.cert.org/vuls/id/287771 | XF:cisco-vpn-spi-bo(9819) | URL:http://www.iss.net/security_center/static/9819.php | XF:cisco-vpn-ike-payload-bo(9820) | URL:http://www.iss.net/security_center/static/9820.php | BID:5441 | URL:http://www.securityfocus.com/bid/5441 | BID:5443 | URL:http://www.securityfocus.com/bid/5443 | Frech> XF:cisco-vpn-spi-bo(9819) | XF:cisco-vpn-ike-payload-bo(9820)  View
5015  CVE-2002-0624  Candidate  Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, aka "Unchecked Buffer in Password Encryption Procedure."  Modified (20061101)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(2) Christey, Cox  Christey> BUGTRAQ:20020614 Microsoft SQL Server 2000 pwdencrypt() buffer overflow | URL:http://online.securityfocus.com/archive/1/276953 | XF:mssql-pwdencrypt-bo(9345) | URL:http://www.iss.net/security_center/static/9345.php | BID:5014 | URL:http://online.securityfocus.com/bid/5014 | Christey> CERT:CA-2002-22 | CERT-VN:VU#225555 | Frech> XF:mssql-pwdencrypt-bo(9345)  View

Page 19884 of 20943, showing 5 records out of 104715 total, starting on record 99416, ending on 99420

Actions