CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5039  CVE-2002-0649  Candidate  Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption, as exploited by the Slammer/Sapphire worm.  Modified (20080207)  ACCEPT(4) Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(2) Christey, Cox  Christey> CERT:CA-2002-22 | CERT-VN:VU#399260 | CERT-VN:VU#484891 | Christey> XF:mssql-resolution-service-bo(9661) | URL:http://www.iss.net/security_center/static/9661.php | BID:5310 | URL:http://www.securityfocus.com/bid/5310 | BID:5311 | URL:http://www.securityfocus.com/bid/5311 | Christey> add to desc: "as exploited by the SQL Slammer/Sapphire worm" | to facilitate matching. | Frech> XF:mssql-resolution-service-bo(9661)  View
6860  CVE-2003-0031  Candidate  Multiple buffer overflows in libmcrypt before 2.5.5 allow attackers to cause a denial of service (crash).  Modified (20080207)  ACCEPT(3) Armstrong, Cole, Green | NOOP(2) Christey, Cox | REVIEWING(1) Jones  Jones> [JHJ] service crash or system crash? | Christey> XF:libmcrypt-multiple-bo(10987) | URL:http://www.iss.net/security_center/static/10987.php | BID:6510 | URL:http://www.securityfocus.com/bid/6510  View
6875  CVE-2003-0046  Candidate  AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.  Modified (20080207)  ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Wall  Green> PRODUCT ANNOUNCEMENT CONTAINS VENDOR ACKNOWLEDGEMENT  View
3606  CVE-2001-0800  Candidate  lpsched in IRIX 6.5.13f and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.  Modified (20080211)  ACCEPT(5) Armstrong, Baker, Bishop, Cole, Foat | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF;irix-lpsched-execute-commands(7642)  View
3128  CVE-2001-0307  Candidate  Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request for a CGI program that does not exist.  Modified (20080213)  MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Bishop  Frech> XF:bajie-execute-shell(6117)  View

Page 20492 of 20943, showing 5 records out of 104715 total, starting on record 102456, ending on 102460

Actions