CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5741 | CVE-2002-1357 | Candidate | Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite. | Modified (20090302) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(1) Cox | REVIEWING(1) Wall | Frech> XF:ssh-transport-length-bo(10868) | View |
903 | CVE-1999-0923 | Candidate | Sample runnable code snippets in ColdFusion Server 4.0 allow remote attackers to read files, conduct a denial of service, or use the server as a proxy for other HTTP calls. | Proposed (20010214) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(1) Christey | Frech> XF:coldfusion-source-display(1741) | XF:coldfusion-syntax-checker(1742) | XF:coldfusion-file-existence(1743) | XF:coldfusion-sourcewindow(1744) | Christey> List all affected runnable code snippets to facilitate | search, which may include: | viewexample.cfm (though could that be part of CVE-1999-0922?) | View |
92 | CVE-1999-0092 | Candidate | Various vulnerabilities in the AIX portmir command allows local users to obtain root access. | Proposed (19990623) | ACCEPT(2) Baker, Bollinger | MODIFY(1) Frech | NOOP(1) Ozancin | Frech> XF:ibm-portmir | View |
452 | CVE-1999-0453 | Candidate | An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP). | Modified (20040512-02) | ACCEPT(2) Baker, Balinsky | MODIFY(1) Frech | NOOP(2) Northcutt, Wall | REVIEWING(1) Christey | Frech> XF:cisco-ident(2289) | ADDREF BUGTRAQ:19990118 Remote Cisco Identification | In description, probably better to use "Cisco" as product/company name. | Balinsky> CiscoSecure IDS has a signature for this...ID 3602 Cisco IOS Identity. | Christey> There may be a slight abstraction problem here, e.g. look | at the candidate for queso/nmap; also see followup Bugtraq post | from "Basement Research" on 19990120 which says that there are | many other features in Cisco products that allow remote | identification. | Christey> fix typo: "Dicsovery" | View |
8768 | CVE-2004-0340 | Candidate | Stack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Server 3.10 allows local users to execute arbitrary code via long (1) LIST, (2) NLST, or (3) STAT commands. | Modified (20050719) | ACCEPT(2) Armstrong, Wall | NOOP(2) Cole, Cox | View |
Page 20176 of 20943, showing 5 records out of 104715 total, starting on record 100876, ending on 100880