CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5593  CVE-2002-1209  Candidate  Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files via ".." (dot-dot backslash) sequences in a GET request.  Modified (20071101)  ACCEPT(2) Baker, Green | NOOP(3) Cole, Cox, Wall  Green> EXPLOIT  View
5596  CVE-2002-1212  Candidate  Buffer overflow in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.  Modified (20071101)  ACCEPT(2) Armstrong, Cole | NOOP(3) Balinsky, Cox, Wall  Balinsky> Links to software are dead. Cannot verify.  View
5363  CVE-2002-0975  Candidate  Buffer overflow in Microsoft DirectX Files Viewer ActiveX control (xweb.ocx) 2.0.6.15 and earlier allows remote attackers to execute arbitrary via a long File parameter.  Modified (20071101)  MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Cox, Foat | REVIEWING(1) Wall  Christey> ADDREF MS:MS02-066 - "the patch sets the Kill Bit on a legacy | DirectX ActiveX control which has been retired but which has a | security vulnerability." | ADDREF MSKB:Q810202 - deals with "a security vulnerability | that exists in the DirectX Files Viewer control (Xweb.ocx)" | | Thanks to Andrew G. Tereschenko (the researcher) for this | additional information. | Frech> XF:ms-directx-files-viewer-bo(9877) | Christey> fix typo: "execute arbitrary [CODE]"  View
5111  CVE-2002-0721  Candidate  Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.  Modified (20071101)  ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(2) Foat, Frech | NOOP(2) Christey, Cox  Foat> The description should list MSDE 1.0 and MSDE 2000 as acknowledged by | Microsoft. | Christey> CERT-VN:VU#818939 | URL:http://www.kb.cert.org/vuls/id/818939 | CERT-VN:VU#939675 | URL:http://www.kb.cert.org/vuls/id/939675 | CERT-VN:VU#399531 | URL:http://www.kb.cert.org/vuls/id/399531 | BID:5481 | URL:http://www.securityfocus.com/bid/5481 | XF:mssql-xp-weak-permissions(9857) | URL:http://www.iss.net/security_center/static/9857.php | Frech> XF:mssql-xp-weak-permissions(9857)  View
8457  CVE-2004-0029  Candidate  Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges.  Modified (20071113)  ACCEPT(2) Armstrong, Baker | NOOP(4) Cole, Cox, Wall, Williams  Williams> insufficient data.  View

Page 20478 of 20943, showing 5 records out of 104715 total, starting on record 102386, ending on 102390

Actions