CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3722 | CVE-2001-0916 | Candidate | Buffer overflow in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privileges via a long check argument of a shell definition. | Modified (20050703) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | Frech> XF:pmake-shell-bo(7603) | Baker> A check of the latest version of pmake, version 2.1.36 reveals that the author lists the format string error as having been corrected. | ftp://ftp.icsi.berkeley.edu/pub/speech/stolcke/software/pmake-2.1.36.tar.Z | | This should be sufficient for vendor acknowledgement. | View |
3741 | CVE-2001-0935 | Candidate | Vulnerability in wu-ftpd 2.6.0, and possibly earlier versions, which is unrelated to the ftpglob bug described in CVE-2001-0550. | Proposed (20020131) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | Frech> XF:wuftp-glob-heap-corruption(7611) | View |
2467 | CVE-2000-0898 | Candidate | Small HTTP Server 2.01 does not properly process Server Side Includes (SSI) tags that contain null values, which allows local users, and possibly remote attackers, to cause the server to crash by inserting the SSI into an HTML file. | Proposed (20001219) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Armstrong, Balinsky, Cole, Wall | Frech> XF:small-http-ssi-dos(5960) | Balinsky> Found no data on vendor web site to support this. | http://home.lanck.net/mf/srv/index.htm | View |
2468 | CVE-2000-0899 | Candidate | Small HTTP Server 2.01 allows remote attackers to cause a denial of service by connecting to the server and sending out multiple GET, HEAD, or POST requests and closing the connection before the server responds to the requests. | Proposed (20001219) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Armstrong, Balinsky, Cole, Wall | Frech> XF:small-http-request-dos(5523) | Balinsky> Found no data on vendor web site to support this. | http://home.lanck.net/mf/srv/index.htm | View |
107 | CVE-1999-0107 | Candidate | Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters. | Modified (19991223-01) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Northcutt, Shostack, Wall | REVIEWING(1) Levy | REVOTE(1) Christey | Wall> - Although this is probably the phf hack. | Frech> XF:apache-dos | Christey> This sounds like the incident reported in: | NTBUGTRAQ:20000810 Apache Distributed Denial of Service | Levy> I belive this is the problem where sending lot of HTTP headers to apache resulted on a denial of service. | BUGTRAQ: http://www.securityfocus.com/archive/1/10228 | BUGTRAQ: http://www.securityfocus.com/archive/1/10516 | View |
Page 20317 of 20943, showing 5 records out of 104715 total, starting on record 101581, ending on 101585