CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6886  CVE-2003-0057  Candidate  Multiple buffer overflows in Hypermail 2 before 2.1.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code (1) via a long attachment filename that is not properly handled by the hypermail executable, or (2) by connecting to the mail CGI program from an IP address that reverse-resolves to a long hostname.  Modified (20071113)  ACCEPT(3) Baker, Cole, Green | NOOP(3) Christey, Cox, Wall  Christey> BID:6689 | BID:6690 | DEBIAN:DSA-248 | SUSE:SuSE-SA:2003:012  View
5360  CVE-2002-0972  Candidate  Buffer overflows in PostgreSQL 7.2 allow attackers to cause a denial of service and possibly execute arbitrary code via long arguments to the functions (1) lpad or (2) rpad.  Modified (20071113)  MODIFY(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall  Christey> SUSE:SuSE-SA:2002:039 | Christey> There are numerous PostgreSQL issues that were reported around | the same time frame. Need to make sure that they are all | properly identified. | Christey> CONFIRM:http://marc.theaimsgroup.com/?l=postgresql-announce&m=103062536330644 | CONFIRM:http://archives.postgresql.org/pgsql-announce/2002-08/msg00004.php | CONECTIVA:CLA-2002:524 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000524 | SUSE:SuSE-SA:2002:038 | URL:http://www.suse.de/de/security/2002_038_postgresql.html | BUGTRAQ:20020826 GLSA: PostgreSQL | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=103036987114437&w=2 | BUGTRAQ:20020824 Fwd: [GENERAL] PostgreSQL 7.2.2: Security Release | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=103021186622725&w=2 | Christey> MANDRAKE:MDKSA-2002:062 | URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2002:062 | REDHAT:RHSA-2003:015 | URL:http://www.redhat.com/support/errata/RHSA-2003-015.html | Frech> XF:postgresql-lpad-rpad-bo(9927) | Christey> REDHAT:RHSA-2003:010  View
8433  CVE-2004-0005  Candidate  Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) octal encoding in yahoo_decode that causes a null byte to be written beyond the buffer, (2) octal encoding in yahoo_decode that causes a pointer to reference memory beyond the terminating null byte, (3) a quoted printable string to the gaim_quotedp_decode MIME decoder that causes a null byte to be written beyond the buffer, and (4) quoted printable encoding in gaim_quotedp_decode that causes a pointer to reference memory beyond the terminating null byte.  Modified (20071113)  ACCEPT(5) Armstrong, Baker, Cole, Cox, Green | NOOP(2) Christey, Wall  Christey> CERT-VN:VU#404470 | URL:http://www.kb.cert.org/vuls/id/404470 | CERT-VN:VU#655974 | URL:http://www.kb.cert.org/vuls/id/655974 | CERT-VN:VU#226974 | URL:http://www.kb.cert.org/vuls/id/226974 | CERT-VN:VU#190366 | URL:http://www.kb.cert.org/vuls/id/190366  View
8442  CVE-2004-0014  Candidate  Multiple buffer overflows in the nd WebDAV interface 0.8.2 and earlier allows remote web servers to execute arbitrary code via certain long strings.  Modified (20071113)  ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Williams | NOOP(2) Cox, Wall  Williams> need to change desc. i think this was fixed in 0.8.2. | http://www.gohome.org/nd  View
8445  CVE-2004-0017  Candidate  Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to perform unauthorized database operations.  Modified (20071113)  ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Williams | NOOP(2) Cox, Wall  Williams> i believe this affects phpGroupWare 0.9.14.006 and earlier, and phpGroupWare 0.9.16RC1 and earlier. | http://phpgroupware.org/downloads  View

Page 20486 of 20943, showing 5 records out of 104715 total, starting on record 102426, ending on 102430

Actions