CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8769  CVE-2004-0341  Candidate  WFTPD Pro Server 3.21 Release 1 allocates memory for a command until a 0Ah byte (newline) is sent, which allows local users to cause a denial of service (CPU consumption) by continuing to send a long command that does not contain a newline.  Modified (20050719)  ACCEPT(2) Armstrong, Wall | NOOP(2) Cole, Cox    View
8770  CVE-2004-0342  Candidate  WFTPD Pro Server 3.21 Release 1, with the XeroxDocutech option enabled, allows local users to cause a denial of service (crash) via a (1) MKD or (2) XMKD command that causes an absolute path of 260 characters to be used, which overwrites a cookie with a null character, possibly due to an off-by-one error.  Modified (20050718)  ACCEPT(2) Armstrong, Wall | NOOP(2) Cole, Cox    View
8774  CVE-2004-0346  Candidate  Off-by-one buffer overflow in _xlate_ascii_write() in ProFTPD 1.2.7 through 1.2.9rc2p allows local users to gain privileges via a 1024 byte RETR command.  Proposed (20040318)  ACCEPT(2) Armstrong, Stracener | NOOP(3) Cole, Cox, Wall    View
798  CVE-1999-0818  Candidate  Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable.  Proposed (19991208)  ACCEPT(2) Armstrong, Stracener | MODIFY(4) Cole, Dik, Frech, Prosser | NOOP(1) Baker | REVIEWING(1) Christey  Cole> This can cause code to be executed. | Frech> XF:sol-kcms-conf-netpath-bo | Dik> the bug has nothing to do with kcms_configure; it"s a bug | in libnsl.so. All set-uid executables that trigger this code path are | vulnerable. Sun bug 4295834; fixed in Solaris 8. | Prosser> Okay, I am confused. Based on Casper"s comments and checking | on the Sun patch site, I found the 4295834 bug(4295834 NETPATH security | problem in libnsl) fixed in SunOS 5.4, Patch 101974-37(x86) 101973 (sparc). | Multiple libnsl vulnerabilities was first reported in an 98 Sun Bulletin | #00172 for 5.4 up through 2.6. Was this NETPATH a problem that resurfaced | in 7 (looks like in 5.4 as well) and was fixed in 8? | Christey> Need to dig up my offline email on this. | Christey> May be a duplicate of CVE-1999-0321, whose sole reference | (XF:sun-kcms-configure-bo) no longer exists. Also examine | BID:452 and | BUGTRAQ:19981223 Merry Christmas to Sun! (Was: L0pht NFR N-Code | Modules Updated) | | which are the same as XF:sol-kcms-conf-p-bo(3652), which could | be the new name for XF:sun-kcms-configure-bo.  View
1606  CVE-2000-0028  Candidate  Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.  Modified (20000626-01)  ACCEPT(2) Armstrong, Stracener | MODIFY(2) Frech, Levy | NOOP(1) Baker | RECAST(1) LeBlanc | REVIEWING(1) Christey  Frech> XF:ie-navigateandfind | Christey> May be a duplicate of CVE-2000-0465 according to my | communications with Microsoft people. CVE-2000-0266 may | also be a variant. | Levy> BID 887 | LeBlanc> duplicate  View

Page 20177 of 20943, showing 5 records out of 104715 total, starting on record 100881, ending on 100885

Actions