CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5259 | CVE-2002-0869 | Candidate | Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation." | Modified (20061101) | ACCEPT(3) Cole, Green, Wall | NOOP(1) Cox | View | |
2701 | CVE-2000-1134 | Candidate | Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack. | Modified (20061101) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(1) Wall | REVIEWING(1) Christey | Frech> XF:linux-bash-tmp-symlink(5593) | Christey> Don"t all these shell programs originate from the same | codebase, including ksh? If so, we should have a single CAN | for all of these, and add: | XF:ksh-redirection-symlink | URL:http://xforce.iss.net/static/5811.php | CONECTIVA:CLA-2000:354 | BUGTRAQ:20001208 Immunix OS Security update for tcsh | http://archives.neohapsis.com/archives/linux/immunix/2000-q4/0041.html | BUGTRAQ:20001220 /bin/ksh creates insecure tmp files | http://archives.neohapsis.com/archives/bugtraq/2000-12/0368.html | BUGTRAQ:20001227 IBM Findings: Korn Shell Redirection Race Condition Vulnerability | http://archives.neohapsis.com/archives/bugtraq/2000-12/0473.html | | Also see: http://archives.neohapsis.com/archives/bugtraq/2000-12/0420.html | which gives some shell history which may be of use. | Christey> ADDREF FREEBSD:FreeBSD-SA-01:03 for the bash problem. | Christey> Consider adding BID:2148 if this CAN should include ksh | Christey> SGI:20011103-01-I | URL:ftp://patches.sgi.com/support/free/security/advisories/20011103-01-I | Also, DELREF BID:2148 and BID:1926. Keep BID:2006 | Christey> COMPAQ:SSRT1-41U | URL:http://ftp.support.compaq.com/patches/.new/html/SSRT0742U-59U.shtml | CERT-VN:VU#10277 | URL:http://www.kb.cert.org/vuls/id/10277 | Christey> SGI:20011103-02-P | URL:ftp://patches.sgi.com/support/free/security/advisories/20011103-02-P | Note that this is an update of the other SGI reference. | Christey> CALDERA:CSSA-2001-SCO.24 | URL:ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.24.1/CSSA-2001-SCO.24.1.txt | CERT-VN:VU#10277 | URL:http://www.kb.cert.org/vuls/id/10277 | Christey> Missing BID - BID:1926 | Christey> HP:SSRT3618 | URL:http://archives.neohapsis.com/archives/hp/2003-q3/0042.html | View |
5015 | CVE-2002-0624 | Candidate | Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, aka "Unchecked Buffer in Password Encryption Procedure." | Modified (20061101) | ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(2) Christey, Cox | Christey> BUGTRAQ:20020614 Microsoft SQL Server 2000 pwdencrypt() buffer overflow | URL:http://online.securityfocus.com/archive/1/276953 | XF:mssql-pwdencrypt-bo(9345) | URL:http://www.iss.net/security_center/static/9345.php | BID:5014 | URL:http://online.securityfocus.com/bid/5014 | Christey> CERT:CA-2002-22 | CERT-VN:VU#225555 | Frech> XF:mssql-pwdencrypt-bo(9345) | View |
4763 | CVE-2002-0371 | Candidate | Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response. | Modified (20061101) | ACCEPT(4) Baker, Cole, Foat, Wall | NOOP(2) Christey, Cox | Christey> XF:ie-gopher-bo(9247) | URL:http://www.iss.net/security_center/static/9247.php | CERT-VN:VU#440275 | URL:http://www.kb.cert.org/vuls/id/440275 | BID:4930 | URL:http://www.securityfocus.com/bid/4930 | Christey> Investigate: should this include IE 5.01? | Christey> Note: CVE-2002-0646 was accidentally assigned to this issue. | That candidate will be rejected in favor of this one. | | ADDREF MS:MS02-047 | | ADDREF BUGTRAQ:20020729 Re: Eat gopher! | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=102796732424646&w=2 | View |
5031 | CVE-2002-0641 | Candidate | Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers with database administration privileges to execute arbitrary code via a long filename in the BULK INSERT query. | Modified (20061101) | ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(2) Christey, Cox | Christey> XF:mssql-bulk-insert-bo(9522) | URL:http://www.iss.net/security_center/static/9522.php | BID:4847 | URL:http://www.securityfocus.com/bid/4847 | Frech> XF:mssql-bulk-insert-bo(9522) | View |
Page 20463 of 20943, showing 5 records out of 104715 total, starting on record 102311, ending on 102315