CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5067 | CVE-2002-0677 | Candidate | CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure. | Modified (20071129) | ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(1) Frech | NOOP(3) Christey, Cox, Foat | Christey> XF:tooltalk-ttdbserverd-ttisclose-validation(9526) | URL:http://www.iss.net/security_center/static/9526.php | BID:5082 | URL:http://www.securityfocus.com/bid/5082 | | HP:HPSBUX0207-199 | URL:http://archives.neohapsis.com/archives/hp/2002-q3/0011.html | Note: while the HP advisory discusses "buffer overflows," | it specifically mentions CA-2002-20, and the text of the | advisory is included in vendor statements for the CERT-VU"s for both | ToolTalk issues covered by CA-2002-20. | | AIXAPAR:IY32368 | URL:http://archives.neohapsis.com/archives/aix/2002-q3/0002.html | AIXAPAR:IY32370 | URL:http://archives.neohapsis.com/archives/aix/2002-q3/0002.html | Christey> HP:HPSBUX0207-199 | URL:http://online.securityfocus.com/advisories/4290 | Christey> SGI:20021101-01-P | Christey> Sun confirmed via email to Matt Wojcik (of MITRE"s OVAL | project) that Sun alert 46022 also addresses this issue. | Frech> XF:tooltalk-ttdbserverd-ttisclose-validation(9526) | View |
5260 | CVE-2002-0870 | Candidate | The original patch for the Cisco Content Service Switch 11000 Series authentication bypass vulnerability (CVE-2001-0622) was incomplete, which still allows remote attackers to gain additional privileges by directly requesting the web management URL instead of navigating through the interface, possibly via a variant of the original attack, as identified by Cisco bug ID CSCdw08549. | Proposed (20020830) | ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(1) Frech | NOOP(2) Cox, Foat | Frech> XF:cisco-css-web-management(6631) | View |
8525 | CVE-2004-0097 | Candidate | Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol. | Modified (20100819) | ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(1) Cox | NOOP(1) Christey | Cox> Addref: REDHAT:RHSA-2004:048 | Be useful to mention OpenH323 and/or H.323 in this text to aid | searching on this issue | Christey> BUGTRAQ:20040409 [ GLSA 200404-11 ] Multiple Vulnerabilities in pwlib | View |
728 | CVE-1999-0748 | Candidate | Buffer overflows in Red Hat net-tools package. | Proposed (19991214) | ACCEPT(4) Armstrong, Baker, Cole, Stracener | MODIFY(1) Frech | REJECT(1) Blake | Blake> RHSA-1999:017-01 describes "potential security problem fixed" in the | absence of knowing whether or not the problems actually existed, I don"t | think we have an entry here. | Frech> XF:redhat-net-tool-bo | View |
802 | CVE-1999-0822 | Candidate | Buffer overflow in Qpopper (qpop) 3.0 allows remote root access via AUTH command. | Proposed (19991208) | ACCEPT(4) Armstrong, Baker, Cole, Stracener | MODIFY(1) Frech | NOOP(1) Christey | REVIEWING(1) Prosser | Frech> XF:qpopper-auth-bo | Christey> ADDREF? DEBIAN:19991215 buffer overflow in qpopper v3.0 | ADDREF XF:qpopper-auth-bo | View |
Page 19944 of 20943, showing 5 records out of 104715 total, starting on record 99716, ending on 99720