CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5039 | CVE-2002-0649 | Candidate | Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption, as exploited by the Slammer/Sapphire worm. | Modified (20080207) | ACCEPT(4) Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(2) Christey, Cox | Christey> CERT:CA-2002-22 | CERT-VN:VU#399260 | CERT-VN:VU#484891 | Christey> XF:mssql-resolution-service-bo(9661) | URL:http://www.iss.net/security_center/static/9661.php | BID:5310 | URL:http://www.securityfocus.com/bid/5310 | BID:5311 | URL:http://www.securityfocus.com/bid/5311 | Christey> add to desc: "as exploited by the SQL Slammer/Sapphire worm" | to facilitate matching. | Frech> XF:mssql-resolution-service-bo(9661) | View |
6860 | CVE-2003-0031 | Candidate | Multiple buffer overflows in libmcrypt before 2.5.5 allow attackers to cause a denial of service (crash). | Modified (20080207) | ACCEPT(3) Armstrong, Cole, Green | NOOP(2) Christey, Cox | REVIEWING(1) Jones | Jones> [JHJ] service crash or system crash? | Christey> XF:libmcrypt-multiple-bo(10987) | URL:http://www.iss.net/security_center/static/10987.php | BID:6510 | URL:http://www.securityfocus.com/bid/6510 | View |
6875 | CVE-2003-0046 | Candidate | AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials. | Modified (20080207) | ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Wall | Green> PRODUCT ANNOUNCEMENT CONTAINS VENDOR ACKNOWLEDGEMENT | View |
3606 | CVE-2001-0800 | Candidate | lpsched in IRIX 6.5.13f and earlier allows remote attackers to execute arbitrary commands via shell metacharacters. | Modified (20080211) | ACCEPT(5) Armstrong, Baker, Bishop, Cole, Foat | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF;irix-lpsched-execute-commands(7642) | View |
3128 | CVE-2001-0307 | Candidate | Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request for a CGI program that does not exist. | Modified (20080213) | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Bishop | Frech> XF:bajie-execute-shell(6117) | View |
Page 20492 of 20943, showing 5 records out of 104715 total, starting on record 102456, ending on 102460