CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5565 | CVE-2002-1181 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the IISHELP virtual directory, or (2) possibly other unknown attack vectors. | Modified (20061101) | ACCEPT(3) Cole, Green, Wall | NOOP(1) Cox | View | |
4548 | CVE-2002-0154 | Candidate | Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of service or execute arbitrary code via a database query with certain long arguments. | Modified (20061101) | ACCEPT(5) Armstrong, Cole, Foat, Green, Wall | MODIFY(1) Frech | NOOP(2) Christey, Cox | Christey> BID:4231 | URL:http://www.securityfocus.com/bid/4231 | XF:mssql-xp-dirtree-bo(8359) | URL:http://www.iss.net/security_center/static/8359.php | | Need to specifically mention xp_dirtree. | Christey> CERT:CA-2002-22 | CERT-VN:VU#627275 | Frech> XF:mssql-multiple-xp-bo(8359) | View |
716 | CVE-1999-0736 | Candidate | The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | Modified (20061101) | ACCEPT(4) Ozancin, Prosser, Stracener, Wall | MODIFY(2) Cole, Frech | NOOP(1) Baker | REVIEWING(1) Christey | Frech> XF:iis-samples-showcode | Cole> There are several sample files that allow this. I would quote | showcode.asp but make it more generic. | Prosser> (Modify) | Have a question on this and on the following three candidates as well. All | of these are part of the file viewers utilities that allow unauthorized | files reading, but MSKB Q231368 also mentioned the diagnostics | program,Winmsdp.exe, as another vulnerable viewer in this same set of | viewers. If we are going to split out the seperate viewer tools then | shouldn"t there should be a seperate CAN for Winmsdp.exe also. | Christey> Mike"s question basically touches on the CD:SF-EXEC | content decision - what do you do when you have the same bug | in multiple executables? CD:SF-EXEC needs to be reviewed | and approved by the Editorial Board before we can decide | what to do with this candidate. | Christey> Mark Burnett says that Microsoft"s mention of winmsdp.exe in | MSKB:Q231368 may be an error, and that winmsdp.exe is a | Microsoft Diagnostics Report Generator which may not even | be installed as part of IIS. | | Also see http://www.securityfocus.com/focus/microsoft/iis/showcode.html | Christey> ADDREF BID:167 | URL:http://www.securityfocus.com/vdb/bottom.html?vid=167 | Christey> MISC:http://p.ulh.as/xploitsdb/NT/iis38.html covers a showcode.asp | directory traversal vulnerability and refers to the L0pht advisory. | | Mark Burnett"s article is at: | MISC:http://www.securityfocus.com/infocus/1317 | View |
7642 | CVE-2003-0818 | Candidate | Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings. | Modified (20061101) | ACCEPT(4) Armstrong, Baker, Cole, Wall | NOOP(2) Christey, Cox | Christey> Various sources say that Windows Server 2003 is also affected. | | XF:win-asn1-library-bo(15039) | URL:http://xforce.iss.net/xforce/xfdb/15039 | BID:9633 | URL:http://www.securityfocus.com/bid/9633 | EEYE:AD20040210-2 | URL:http://www.eeye.com/html/Research/Advisories/AD20040210-2.html | View |
5083 | CVE-2002-0693 | Candidate | Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function. | Modified (20061101) | ACCEPT(3) Cole, Green, Wall | NOOP(1) Cox | View |
Page 20464 of 20943, showing 5 records out of 104715 total, starting on record 102316, ending on 102320