CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3952  CVE-2001-1148  Candidate  Multiple buffer overflows in programs used by scoadmin and sysadmsh in SCO OpenServer 5.0.6a and earlier allow local users to gain privileges via a long TERM environment variable to (1) atcronsh, (2) auditsh, (3) authsh, (4) backupsh, (5) lpsh, (6) sysadm.menu, or (7) termsh.  Modified (20050707)  ACCEPT(4) Armstrong, Baker, Cole, Green | MODIFY(1) Frech | NOOP(3) Foat, Wall, Ziese  Frech> XF:openserver-scoadmin-sysadm-bo(7281)  View
4485  CVE-2002-0091  Candidate  Multiple CGI scripts in CIDER SHADOW 1.5 and 1.6 allows remote attackers to execute arbitrary commands via certain form fields.  Modified (20050707)  ACCEPT(2) Cole, Green | NOOP(4) Christey, Foat, Wall, Ziese  Christey> VULNWATCH:20020429 [VulnWatch] eSecurityOnline Security Advisory 2408 - CIDER SHADOW CGI | URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0038.html | BID:4625 | URL:http://www.securityfocus.com/bid/4625 | BUGTRAQ:20020429 eSecurityOnline Security Advisory 2408 - CIDER SHADOW CGI | URL:http://online.securityfocus.com/archive/1/270111  View
4496  CVE-2002-0102  Candidate  Oracle9iAS Web Cache 2.0.0.x allows remote attackers to cause a denial of service via (1) a request to TCP ports 1100, 4000, 4001, and 4002 with a large number of null characters, and (2) a request to TCP port 4000 with a large number of "." characters.  Modified (20050707)  ACCEPT(4) Cole, Foat, Green, Ziese | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:oracle-appserver-admin-dos(7310) | XF:oracle-appserver-null-dos(7765) | CHANGE> [Foat changed vote from NOOP to ACCEPT]  View
4506  CVE-2002-0112  Candidate  Etype Eserv 2.97 allows remote attackers to view password protected files via /./ in the URL.  Modified (20050707)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall  Green> Vendor has released upgrades | Frech> XF:eserv-protected-file-access(7849) | ADDREF:http://online.securityfocus.com/archive/1/249210  View
4534  CVE-2002-0140  Candidate  Domain Name Relay Daemon (dnrd) 2.10 and earlier allows remote malicious DNS sites to cause a denial of service and possibly execute arbitrary code via a long or malformed DNS reply, which is not handled properly by parse_query, get_objectname, and possibly other functions.  Modified (20050707)  ACCEPT(2) Foat, Green | MODIFY(1) Frech | NOOP(2) Cole, Wall  Frech> XF:dnrd-dns-dos(7957)  View

Page 20445 of 20943, showing 5 records out of 104715 total, starting on record 102221, ending on 102225

Actions