CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5160  CVE-2002-0770  Candidate  Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute Q2 server admin commands via a client that does not expand "$" macros, which causes the server to expand the macros and leak the information, as demonstrated using "say $rcon_password."  Modified (20051128)  NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
5159  CVE-2002-0769  Candidate  The web-based configuration interface for the Cisco ATA 186 Analog Telephone Adaptor allows remote attackers to bypass authentication via an HTTP POST request with a single byte, which allows the attackers to (1) obtain the password from the login screen, or (2) reconfigure the adaptor by modifying certain request parameters.  Proposed (20020726)  ACCEPT(3) Armstrong, Baker, Cole | NOOP(3) Cox, Foat, Wall    View
5158  CVE-2002-0768  Entry  Buffer overflow in lukemftp FTP client in SuSE 6.4 through 8.0, and possibly other operating systems, allows a malicious FTP server to execute arbitrary code via a long PASV command.        View
5157  CVE-2002-0767  Candidate  simpleinit on Linux systems does not close a read/write FIFO file descriptor before creating a child process, which allows the child process to cause simpleinit to execute arbitrary programs with root privileges.  Proposed (20020726)  NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
5156  CVE-2002-0766  Entry  OpenBSD 2.9 through 3.1 allows local users to cause a denial of service (resource exhaustion) and gain root privileges by filling the kernel"s file descriptor table and closing file descriptors 0, 1, or 2 before executing a privileged process, which is not properly handled when OpenBSD fails to open an alternate descriptor.        View

Page 19912 of 20943, showing 5 records out of 104715 total, starting on record 99556, ending on 99560

Actions