CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3422 | CVE-2001-0609 | Candidate | Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog function. | Modified (20040818) | ACCEPT(5) Baker, Bishop, Cole, Frech, Ziese | NOOP(2) Foat, Wall | REVIEWING(1) Christey | Christey> A very similar vulnerability - which perhaps should be | combined with this CAN according to CD:SF-LOC - is documented | in the following references: | | BUGTRAQ:20010621 cfingerd local vulnerability (possibly root) | URL:http://www.securityfocus.com/archive/1/Pine.LNX.4.33.0106212246190.31927-100000@ace | BUGTRAQ:20010712 Happy 3 month anniversary cfingerd remote bug! | URL:http://www.securityfocus.com/archive/1/Pine.LNX.4.33.0107120434070.10330-200000@clarity.local | BID:2915 | URL:http://www.securityfocus.com/bid/2915 | Christey> DELREF DEBIAN:DSA-048 [wrong CVE] | View |
2933 | CVE-2001-0112 | Candidate | Multiple buffer overflows in splitvt before 1.6.5 allow local users to execute arbitrary commands. | Modified (20040818) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF:splitvt-bo(6210) | View |
4767 | CVE-2002-0375 | Candidate | Cross-site scripting vulnerability in sgdynamo.exe for Sgdynamo allows remote attackers to execute arbitrary Javascript via a URL with the script in the HTNAME parameter. | Modified (20040818) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | Frech> XF:sgdynamo-htname-parameter-xss(9830) | View |
5073 | CVE-2002-0683 | Candidate | Directory traversal vulnerability in Carello 1.3 allows remote attackers to execute programs on the server via a .. (dot dot) in the VBEXE parameter. | Modified (20040818) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall | Christey> XF:carello-local-file-execution(9521) | URL:http://www.iss.net/security_center/static/9521.php | BID:5192 | URL:http://www.securityfocus.com/bid/5192 | Christey> VULNWATCH:20021002 wp-02-0012: Carello 1.3 Remote File Execution (Updated 1/10/2002) | Frech> XF:carello-local-file-execution(9521) | View |
5074 | CVE-2002-0684 | Candidate | Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by functions such as getnetbyname and getnetbyaddr. | Modified (20040818) | ACCEPT(5) Baker, Cole, Foat, Green, Wall | MODIFY(2) Cox, Frech | NOOP(1) Christey | Cox> RHSA-2002:133 is CVE-2002-0651 not this one, ADDREF:RHSA-2002:167 | Christey> HP:HPSBUX0209-218 | URL:http://archives.neohapsis.com/archives/hp/2002-q3/0087.html | Frech> XF:dns-resolver-lib-bo(9432) | Christey> DELREF REDHAT:RHSA-2002:133 | Christey> DELREF REDHAT:RHSA-2002:133 | View |
Page 20404 of 20943, showing 5 records out of 104715 total, starting on record 102016, ending on 102020