CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5050  CVE-2002-0660  Candidate  Buffer overflow in libpng 1.0.12-3.woody.2 and libpng3 1.2.1-1.1.woody.2 on Debian GNU/Linux 3.0, and other operating systems, may allow attackers to cause a denial of service and possibly execute arbitrary code, a different vulnerability than CVE-2002-0728.  Modified (20041020)  ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(2) Cox, Frech | NOOP(2) Christey, Foat  Cox> No need to single out woody and Debian Linux, this affects | libpng that is used throughout Linux distributions. | Christey> CALDERA:CSSA-2002-042.0 | URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-042.0.txt | Christey> Need to change desc a bit - say it"s 1.0.12, remove Debian | specifics. | XF:libpng-wide-image-bo(9790) | URL:http://www.iss.net/security_center/static/9790.php | BID:5409 | URL:http://www.securityfocus.com/bid/5409 | CALDERA:CSSA-2002-042.0 | URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-042.0.txt | Frech> XF:libpng-wide-image-bo(9790) | Christey> Change "Debian Linux" to "Debian GNU/Linux"  View
5049  CVE-2002-0659  Candidate  The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings.  Proposed (20020830)  ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Cox | NOOP(2) Christey, Foat  Cox> ADDREF:RHSA-2002:163 RHSA-2002:184 | add "and possibly arbitrary code execution" | This issue also affects SSLeay and BSAFE SSL-C | ADDREF: http://www.rsasecurity.com/products/bsafe/bulletins/BSAFE_SSL_Products_Security_Bulletin_Aug_8_2002.pdf | Christey> CONFIRM:http://www.cisco.com/univercd/cc/td/doc/product/webscale/css/css_sca/sca_320/v320b20.htm#xtocid13 | Christey> I should probably create a separate CAN for the BSAFE issues, | unless there is a codebase relationship.  View
5048  CVE-2002-0658  Entry  OSSP mm library (libmm) before 1.2.0 allows the local Apache user to gain privileges via temporary files, possibly via a symbolic link attack.        View
5047  CVE-2002-0657  Candidate  Buffer overflow in OpenSSL 0.9.7 before 0.9.7-beta3, with Kerberos enabled, allows attackers to execute arbitrary code via a long master key.  Proposed (20020830)  ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Cox | NOOP(2) Christey, Foat  Cox> The majority of the vendor references listed are incorrect, those vendors | did not ship 0.9.7. Each one should be checked for accuracy, those | not shipping 0.9.7 were not affected. | Christey> CONFIRM:http://www.cisco.com/univercd/cc/td/doc/product/webscale/css/css_sca/sca_320/v320b20.htm#xtocid13  View
5046  CVE-2002-0656  Candidate  Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3.  Modified (20071016)  ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Cox | NOOP(2) Christey, Foat  Christey> The CVE content decision "CD:SF-LOC" recommends that multiple | bugs of the same type, in the same version of software, should | be combined. Content decisions such as CD:SF-LOC ensure the | long-term consistency of CVE across all vulnerability reports, | since the amount of detail can vary widely. | Cox> ADDREF:RHSA-2002:163 RHSA-2002:164 RHSA-2002:157 | This issue also affects SSLeay and BSAFE SSL-C | ADDREF: http://www.rsasecurity.com/products/bsafe/bulletins/BSAFE_SSL_Products_Security_Bulletin_Aug_8_2002.pdf | Christey> BUGTRAQ:20021003 Cisco Secure Content Accelerator vulnerable to SSL worm | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=103374616018622&w=2 | CONFIRM:http://www.cisco.com/univercd/cc/td/doc/product/webscale/css/css_sca/sca_320/v320b20.htm#xtocid13 | Christey> I should probably create a separate CAN for the BSAFE issues, | unless there is a codebase relationship. | Christey> XF:openssl-ssl3-sessionid-bo(9716) | URL:http://www.iss.net/security_center/static/9716.php  View

Page 19934 of 20943, showing 5 records out of 104715 total, starting on record 99666, ending on 99670

Actions