CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6886  CVE-2003-0057  Candidate  Multiple buffer overflows in Hypermail 2 before 2.1.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code (1) via a long attachment filename that is not properly handled by the hypermail executable, or (2) by connecting to the mail CGI program from an IP address that reverse-resolves to a long hostname.  Modified (20071113)  ACCEPT(3) Baker, Cole, Green | NOOP(3) Christey, Cox, Wall  Christey> BID:6689 | BID:6690 | DEBIAN:DSA-248 | SUSE:SuSE-SA:2003:012  View
4404  CVE-2002-0010  Candidate  Bugzilla before 2.14.1 allows remote attackers to inject arbitrary SQL code and create files or gain privileges via (1) the sql parameter in buglist.cgi, (2) invalid field names from the "boolean chart" query in buglist.cgi, (3) the mybugslink parameter in userprefs.cgi, (4) a malformed bug ID in the buglist parameter in long_list.cgi, and (5) the value parameter in editusers.cgi, which allows groupset privileges to be modified by attackers with blessgroupset privileges.  Modified (20050703)  ACCEPT(3) Baker, Cole, Green | NOOP(2) Foat, Wall | REVIEWING(1) Frech  Frech> XF:bugzilla-buglist-modify-sql(7807) | XF:bugzilla-userprefs-change-groupset(7809) | XF:bugzilla-longlist-modify-sql(7811) | XF:bugzilla-editusers-change-groupset(7814) | XF:bugzilla-buglist-sql-logic(7813)  View
5667  CVE-2002-1283  Candidate  Buffer overflow in Novell iManager (eMFrame) before 1.5 allows remote attackers to cause a denial of service via an authentication request with a long Distinguished Name (DN) attribute.  Modified (20081001)  ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Wall | REVIEWING(1) Christey  Christey> Consider overlap with CVE-2002-1002 ? | See XF:novell-imanager-username-bo(9444) for more info  View
5907  CVE-2002-1523  Candidate  Directory traversal vulnerability in Daniel Arenz Mini Server 2.1.6 allows remote attackers to read arbitrary files via (1) ../ (dot-dot slash) or (2) .. (dot-dot backslash) sequences.  Proposed (20030317)  ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Wall    View
6875  CVE-2003-0046  Candidate  AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.  Modified (20080207)  ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Wall  Green> PRODUCT ANNOUNCEMENT CONTAINS VENDOR ACKNOWLEDGEMENT  View

Page 20009 of 20943, showing 5 records out of 104715 total, starting on record 100041, ending on 100045

Actions