CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3422  CVE-2001-0609  Candidate  Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog function.  Modified (20040818)  ACCEPT(5) Baker, Bishop, Cole, Frech, Ziese | NOOP(2) Foat, Wall | REVIEWING(1) Christey  Christey> A very similar vulnerability - which perhaps should be | combined with this CAN according to CD:SF-LOC - is documented | in the following references: | | BUGTRAQ:20010621 cfingerd local vulnerability (possibly root) | URL:http://www.securityfocus.com/archive/1/Pine.LNX.4.33.0106212246190.31927-100000@ace | BUGTRAQ:20010712 Happy 3 month anniversary cfingerd remote bug! | URL:http://www.securityfocus.com/archive/1/Pine.LNX.4.33.0107120434070.10330-200000@clarity.local | BID:2915 | URL:http://www.securityfocus.com/bid/2915 | Christey> DELREF DEBIAN:DSA-048 [wrong CVE]  View
2933  CVE-2001-0112  Candidate  Multiple buffer overflows in splitvt before 1.6.5 allow local users to execute arbitrary commands.  Modified (20040818)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:splitvt-bo(6210)  View
4767  CVE-2002-0375  Candidate  Cross-site scripting vulnerability in sgdynamo.exe for Sgdynamo allows remote attackers to execute arbitrary Javascript via a URL with the script in the HTNAME parameter.  Modified (20040818)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:sgdynamo-htname-parameter-xss(9830)  View
5073  CVE-2002-0683  Candidate  Directory traversal vulnerability in Carello 1.3 allows remote attackers to execute programs on the server via a .. (dot dot) in the VBEXE parameter.  Modified (20040818)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall  Christey> XF:carello-local-file-execution(9521) | URL:http://www.iss.net/security_center/static/9521.php | BID:5192 | URL:http://www.securityfocus.com/bid/5192 | Christey> VULNWATCH:20021002 wp-02-0012: Carello 1.3 Remote File Execution (Updated 1/10/2002) | Frech> XF:carello-local-file-execution(9521)  View
5074  CVE-2002-0684  Candidate  Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by functions such as getnetbyname and getnetbyaddr.  Modified (20040818)  ACCEPT(5) Baker, Cole, Foat, Green, Wall | MODIFY(2) Cox, Frech | NOOP(1) Christey  Cox> RHSA-2002:133 is CVE-2002-0651 not this one, ADDREF:RHSA-2002:167 | Christey> HP:HPSBUX0209-218 | URL:http://archives.neohapsis.com/archives/hp/2002-q3/0087.html | Frech> XF:dns-resolver-lib-bo(9432) | Christey> DELREF REDHAT:RHSA-2002:133 | Christey> DELREF REDHAT:RHSA-2002:133  View

Page 20404 of 20943, showing 5 records out of 104715 total, starting on record 102016, ending on 102020

Actions