CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2922 | CVE-2001-0101 | Candidate | Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command. | Modified (20020222-01) | ACCEPT(4) Baker, Cole, Prosser, Ziese | MODIFY(1) Frech | NOOP(1) Wall | Prosser> TURBO:TLSA2000024-1 | http://www.turbolinux.com/pipermail/tl-security-announce/2000-December/000027.html | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:fetchmail-authenticate-gssapi(7455) | View |
1903 | CVE-2000-0325 | Candidate | The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability. | Modified (20020222-01) | ACCEPT(5) Armstrong, Baker, Cole, Prosser, Wall | MODIFY(1) Frech | REJECT(1) LeBlanc | REVIEWING(1) Christey | LeBlanc> - same as CVE-1999-1011 | If I"m misunderstanding something here, please correct me. In fact, it has | the same bulletin as a reference. | Frech> XF:jet-vba-shell | Prosser> This entry is not the same as "now" CVE-1999-1011. That entry is "The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands." This one should be correct. | Christey> BUGTRAQ:19990525 Advisory: NT ODBC Remote Compromise | http://marc.theaimsgroup.com/?l=bugtraq&m=92765973107637&w=2 | NTBUGTRAQ:19990526 Advisory: NT ODBC Remote Compromise | http://marc.theaimsgroup.com/?l=ntbugtraq&m=92781907215748&w=2 | Christey> The Microsoft advisory itself describes two separate | vulnerabilities, calling the TEXT I-ISAM problem | (CVE-2000-0323) a variant of the VBA Shell problem (this | CAN). In addition, CVE-2000-0323 does *not* appear in Jet | 4.0, while this one does. Since one problem appears in a | different version than the other, CD:SF-LOC suggests keeping | these candidates SPLIT. | | BID:548 | http://www.securityfocus.com/bid/548 | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> Need to clarify whether the Bugtraq/NTBugtraq posts are | really describing the same issue (those are BID:286). | View |
3329 | CVE-2001-0515 | Candidate | Oracle Listener in Oracle 7.3 and 8i allows remote attackers to cause a denial of service via a malformed connection packet with a large offset_to_data value. | Modified (20020223-01) | ACCEPT(4) Armstrong, Cole, Stracener, Ziese | MODIFY(1) Frech | NOOP(2) Foat, Wall | Frech> XF:oracle-listener-offsettodata-dos(6713) | CONFIRM:http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf | View |
3330 | CVE-2001-0516 | Candidate | Oracle listener between Oracle 9i and Oracle 8.0 allows remote attackers to cause a denial of service via a malformed connection packet that contains an incorrect requester_version value that does not match an expected offset to the data. | Modified (20020223-01) | ACCEPT(4) Armstrong, Cole, Stracener, Ziese | MODIFY(1) Frech | NOOP(2) Foat, Wall | Frech> XF:oracle-listener-incorrect-version-dos(6714) | CONFIRM:http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf | View |
3337 | CVE-2001-0523 | Candidate | eEye SecureIIS versions 1.0.3 and earlier allows a remote attacker to bypass filtering of requests made to SecureIIS by escaping HTML characters within the request, which could allow a remote attacker to use restricted variables and perform directory traversal attacks on vulnerable programs that would otherwise be protected. | Modified (20020223-01) | ACCEPT(4) Bishop, Cole, Frech, Ziese | NOOP(2) Foat, Wall | View |
Page 20390 of 20943, showing 5 records out of 104715 total, starting on record 101946, ending on 101950