CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5741  CVE-2002-1357  Candidate  Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.  Modified (20090302)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(1) Cox | REVIEWING(1) Wall  Frech> XF:ssh-transport-length-bo(10868)  View
903  CVE-1999-0923  Candidate  Sample runnable code snippets in ColdFusion Server 4.0 allow remote attackers to read files, conduct a denial of service, or use the server as a proxy for other HTTP calls.  Proposed (20010214)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(1) Christey  Frech> XF:coldfusion-source-display(1741) | XF:coldfusion-syntax-checker(1742) | XF:coldfusion-file-existence(1743) | XF:coldfusion-sourcewindow(1744) | Christey> List all affected runnable code snippets to facilitate | search, which may include: | viewexample.cfm (though could that be part of CVE-1999-0922?)  View
92  CVE-1999-0092  Candidate  Various vulnerabilities in the AIX portmir command allows local users to obtain root access.  Proposed (19990623)  ACCEPT(2) Baker, Bollinger | MODIFY(1) Frech | NOOP(1) Ozancin  Frech> XF:ibm-portmir  View
452  CVE-1999-0453  Candidate  An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP).  Modified (20040512-02)  ACCEPT(2) Baker, Balinsky | MODIFY(1) Frech | NOOP(2) Northcutt, Wall | REVIEWING(1) Christey  Frech> XF:cisco-ident(2289) | ADDREF BUGTRAQ:19990118 Remote Cisco Identification | In description, probably better to use "Cisco" as product/company name. | Balinsky> CiscoSecure IDS has a signature for this...ID 3602 Cisco IOS Identity. | Christey> There may be a slight abstraction problem here, e.g. look | at the candidate for queso/nmap; also see followup Bugtraq post | from "Basement Research" on 19990120 which says that there are | many other features in Cisco products that allow remote | identification. | Christey> fix typo: "Dicsovery"  View
8768  CVE-2004-0340  Candidate  Stack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Server 3.10 allows local users to execute arbitrary code via long (1) LIST, (2) NLST, or (3) STAT commands.  Modified (20050719)  ACCEPT(2) Armstrong, Wall | NOOP(2) Cole, Cox    View

Page 20176 of 20943, showing 5 records out of 104715 total, starting on record 100876, ending on 100880

Actions