CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5111  CVE-2002-0721  Candidate  Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.  Modified (20071101)  ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(2) Foat, Frech | NOOP(2) Christey, Cox  Foat> The description should list MSDE 1.0 and MSDE 2000 as acknowledged by | Microsoft. | Christey> CERT-VN:VU#818939 | URL:http://www.kb.cert.org/vuls/id/818939 | CERT-VN:VU#939675 | URL:http://www.kb.cert.org/vuls/id/939675 | CERT-VN:VU#399531 | URL:http://www.kb.cert.org/vuls/id/399531 | BID:5481 | URL:http://www.securityfocus.com/bid/5481 | XF:mssql-xp-weak-permissions(9857) | URL:http://www.iss.net/security_center/static/9857.php | Frech> XF:mssql-xp-weak-permissions(9857)  View
5050  CVE-2002-0660  Candidate  Buffer overflow in libpng 1.0.12-3.woody.2 and libpng3 1.2.1-1.1.woody.2 on Debian GNU/Linux 3.0, and other operating systems, may allow attackers to cause a denial of service and possibly execute arbitrary code, a different vulnerability than CVE-2002-0728.  Modified (20041020)  ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(2) Cox, Frech | NOOP(2) Christey, Foat  Cox> No need to single out woody and Debian Linux, this affects | libpng that is used throughout Linux distributions. | Christey> CALDERA:CSSA-2002-042.0 | URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-042.0.txt | Christey> Need to change desc a bit - say it"s 1.0.12, remove Debian | specifics. | XF:libpng-wide-image-bo(9790) | URL:http://www.iss.net/security_center/static/9790.php | BID:5409 | URL:http://www.securityfocus.com/bid/5409 | CALDERA:CSSA-2002-042.0 | URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-042.0.txt | Frech> XF:libpng-wide-image-bo(9790) | Christey> Change "Debian Linux" to "Debian GNU/Linux"  View
8535  CVE-2004-0107  Candidate  The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.  Modified (20100819)  ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(2) Cox, Frech | NOOP(1) Christey  Frech> XF:sysstat-post-trigger-symlink(15428) | http://xforce.iss.net/xforce/xfdb/15428 | Cox> This issue is in the vendor packaging of sysstat, not sysstat itself, | and does not apply to a particular version of upstream | sysstat. Suggest "trigger scripts in various vendors packaging of | syssstat allows local users..." or "in the Red Hat packaging of sysstat" | Christey> CIAC:O-097 | URL:http://www.ciac.org/ciac/bulletins/o-097.shtml | XF:sysstat-post-trigger-symlink(15428) | URL:http://xforce.iss.net/xforce/xfdb/15428 | BID:9838 | URL:http://www.securityfocus.com/bid/9838 | Christey> FEDORA:FEDORA-2004-1372 | URL:https://bugzilla.fedora.us/show_bug.cgi?id=1372  View
4425  CVE-2002-0031  Candidate  Buffer overflows in Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary code via a ymsgr URI with long arguments to (1) call, (2) sendim, (3) getimv, (4) chat, (5) addview, or (6) addfriend.  Proposed (20020611)  ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(1) Frech | NOOP(3) Christey, Cox, Foat  Christey> XF:yahoo-messenger-ymsgr-bo(9183) | URL:http://www.iss.net/security_center/static/9183.php | Frech> XF:yahoo-messenger-ymsgr-bo(9183)  View
5247  CVE-2002-0857  Candidate  Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle DBA system by placing format strings into certain entries in the listener.ora configuration file.  Modified (20050510)  ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(1) Frech | NOOP(3) Christey, Cox, Foat  Christey> XF:oracle-lsnrctl-format-string(9832) | URL:http://www.iss.net/security_center/static/9832.php | CERT-VN:VU#301059 | URL:http://www.kb.cert.org/vuls/id/301059 | BID:5460 | URL:http://www.securityfocus.com/bid/5460 | MISC:http://www.nextgenss.com/advisories/ora-lsnrfmtstr.txt | Frech> XF:oracle-lsnrctl-format-string(9832)  View

Page 19943 of 20943, showing 5 records out of 104715 total, starting on record 99711, ending on 99715

Actions