CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6886 | CVE-2003-0057 | Candidate | Multiple buffer overflows in Hypermail 2 before 2.1.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code (1) via a long attachment filename that is not properly handled by the hypermail executable, or (2) by connecting to the mail CGI program from an IP address that reverse-resolves to a long hostname. | Modified (20071113) | ACCEPT(3) Baker, Cole, Green | NOOP(3) Christey, Cox, Wall | Christey> BID:6689 | BID:6690 | DEBIAN:DSA-248 | SUSE:SuSE-SA:2003:012 | View |
4404 | CVE-2002-0010 | Candidate | Bugzilla before 2.14.1 allows remote attackers to inject arbitrary SQL code and create files or gain privileges via (1) the sql parameter in buglist.cgi, (2) invalid field names from the "boolean chart" query in buglist.cgi, (3) the mybugslink parameter in userprefs.cgi, (4) a malformed bug ID in the buglist parameter in long_list.cgi, and (5) the value parameter in editusers.cgi, which allows groupset privileges to be modified by attackers with blessgroupset privileges. | Modified (20050703) | ACCEPT(3) Baker, Cole, Green | NOOP(2) Foat, Wall | REVIEWING(1) Frech | Frech> XF:bugzilla-buglist-modify-sql(7807) | XF:bugzilla-userprefs-change-groupset(7809) | XF:bugzilla-longlist-modify-sql(7811) | XF:bugzilla-editusers-change-groupset(7814) | XF:bugzilla-buglist-sql-logic(7813) | View |
5667 | CVE-2002-1283 | Candidate | Buffer overflow in Novell iManager (eMFrame) before 1.5 allows remote attackers to cause a denial of service via an authentication request with a long Distinguished Name (DN) attribute. | Modified (20081001) | ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Wall | REVIEWING(1) Christey | Christey> Consider overlap with CVE-2002-1002 ? | See XF:novell-imanager-username-bo(9444) for more info | View |
5907 | CVE-2002-1523 | Candidate | Directory traversal vulnerability in Daniel Arenz Mini Server 2.1.6 allows remote attackers to read arbitrary files via (1) ../ (dot-dot slash) or (2) .. (dot-dot backslash) sequences. | Proposed (20030317) | ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Wall | View | |
6875 | CVE-2003-0046 | Candidate | AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials. | Modified (20080207) | ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Wall | Green> PRODUCT ANNOUNCEMENT CONTAINS VENDOR ACKNOWLEDGEMENT | View |
Page 20009 of 20943, showing 5 records out of 104715 total, starting on record 100041, ending on 100045