CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3952 | CVE-2001-1148 | Candidate | Multiple buffer overflows in programs used by scoadmin and sysadmsh in SCO OpenServer 5.0.6a and earlier allow local users to gain privileges via a long TERM environment variable to (1) atcronsh, (2) auditsh, (3) authsh, (4) backupsh, (5) lpsh, (6) sysadm.menu, or (7) termsh. | Modified (20050707) | ACCEPT(4) Armstrong, Baker, Cole, Green | MODIFY(1) Frech | NOOP(3) Foat, Wall, Ziese | Frech> XF:openserver-scoadmin-sysadm-bo(7281) | View |
4485 | CVE-2002-0091 | Candidate | Multiple CGI scripts in CIDER SHADOW 1.5 and 1.6 allows remote attackers to execute arbitrary commands via certain form fields. | Modified (20050707) | ACCEPT(2) Cole, Green | NOOP(4) Christey, Foat, Wall, Ziese | Christey> VULNWATCH:20020429 [VulnWatch] eSecurityOnline Security Advisory 2408 - CIDER SHADOW CGI | URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0038.html | BID:4625 | URL:http://www.securityfocus.com/bid/4625 | BUGTRAQ:20020429 eSecurityOnline Security Advisory 2408 - CIDER SHADOW CGI | URL:http://online.securityfocus.com/archive/1/270111 | View |
4496 | CVE-2002-0102 | Candidate | Oracle9iAS Web Cache 2.0.0.x allows remote attackers to cause a denial of service via (1) a request to TCP ports 1100, 4000, 4001, and 4002 with a large number of null characters, and (2) a request to TCP port 4000 with a large number of "." characters. | Modified (20050707) | ACCEPT(4) Cole, Foat, Green, Ziese | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF:oracle-appserver-admin-dos(7310) | XF:oracle-appserver-null-dos(7765) | CHANGE> [Foat changed vote from NOOP to ACCEPT] | View |
4506 | CVE-2002-0112 | Candidate | Etype Eserv 2.97 allows remote attackers to view password protected files via /./ in the URL. | Modified (20050707) | ACCEPT(1) Green | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | Green> Vendor has released upgrades | Frech> XF:eserv-protected-file-access(7849) | ADDREF:http://online.securityfocus.com/archive/1/249210 | View |
4534 | CVE-2002-0140 | Candidate | Domain Name Relay Daemon (dnrd) 2.10 and earlier allows remote malicious DNS sites to cause a denial of service and possibly execute arbitrary code via a long or malformed DNS reply, which is not handled properly by parse_query, get_objectname, and possibly other functions. | Modified (20050707) | ACCEPT(2) Foat, Green | MODIFY(1) Frech | NOOP(2) Cole, Wall | Frech> XF:dnrd-dns-dos(7957) | View |
Page 20445 of 20943, showing 5 records out of 104715 total, starting on record 102221, ending on 102225