CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1627  CVE-2000-0049  Candidate  Buffer overflow in Winamp client allows remote attackers to execute commands via a long entry in a .pls file.  Modified (20071115)  ACCEPT(2) Cole, Wall | MODIFY(2) Baker, Frech | REVIEWING(1) Christey  Frech> XF:winamp-playlist-bo | Christey> This may have been discovered earlier in: | BUGTRAQ:19990512 Buffer overflow in WinAMP 2.x | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92662988700367&w=2 | See the following for possible confirmation: | URL:http://www.winamp.com/getwinamp/newfeatures.jhtml | Wall> This vulnerability has been seen in several versions of Winamp and part of ISS | X-Force | and SecuriTeam vulnerability checks. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Baker> The old confirm url doesn"t work any more... I am not sure where we can get the old changelog/error list.  View
3537  CVE-2001-0729  Candidate  Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters.  Modified (20071115)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Christey  Christey> The initial description originally stated that this was a | denial of service, but it"s really a directory listing | problem. I changed the description accordingly. | Frech> XF:apache-slash-directory-listing(6921) | Christey> XF:apache-slash-directory-listing(6921) is identifying a | different issue that has not had a CAN assigned yet. | Christey> SGI:20020301-01-P | URL:ftp://patches.sgi.com/support/free/security/advisories/20020301-01-P | Christey> CVE-2001-0925 and CVE-2001-0729 are different issues. | CVE-2001-0925 only applies to versions before 1.3.19, whereas | CVE-2001-0729 applies to 1.3.20, and only Windows. | | The Change Log at http://www.apache.org/dist/httpd/CHANGES_1.3 | specifically mentions these CANs separately.  View
186  CVE-1999-0186  Candidate  In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.  Modified (20071119)  ACCEPT(2) Baker, Dik | MODIFY(1) Frech | NOOP(1) Wall | REVIEWING(1) Christey  Frech> Change XF:snmp-backdoor-access to XF:sol-hidden-commstr | Add ISS:Hidden Community String in SNMP Implementation | Christey> What is the proper level of abstraction to use here? Should | we have a separate entry for each different default community | string? See: | http://cve.mitre.org/Board_Sponsors/archives/msg00242.html and | http://cve.mitre.org/Board_Sponsors/archives/msg00250.html | http://cve.mitre.org/Board_Sponsors/archives/msg00251.html | | Until the associated content decisions have been approved | by the Editorial Board, this candidate cannot be accepted | for inclusion in CVE. | Christey> ADDREF BID:177 | Christey> ISS:19981102 Hidden community string in SNMP implementation | http://xforce.iss.net/alerts/advise11.php | | Change description to include "hidden" | Christey> XF:snmp-backdoor-access is missing.  View
5550  CVE-2002-1166  Candidate  Buffer overflow in John Franks WN Server 1.18.2 through 2.0.0 allows remote attackers to execute arbitrary code via a long GET request.  Modified (20071121)  ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall    View
6854  CVE-2003-0025  Candidate  Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain privileges via certain database functions such as check_prefs() in db.pgsql, as demonstrated using mailbox.php3.  Modified (20071121)  ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Jones | NOOP(2) Christey, Cox  Jones> Change "...gain privileges..." to "...gain additional | privileges..." | Christey> BID:6559 | URL:http://www.securityfocus.com/bid/6559 | XF:imp-multiple-sql-injection(11028) | URL:http://www.iss.net/security_center/static/11028.php | Christey> CONECTIVA:CLA-2003:690 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000690  View

Page 20487 of 20943, showing 5 records out of 104715 total, starting on record 102431, ending on 102435

Actions