CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2069 | CVE-2000-0491 | Candidate | Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY request. | Proposed (20000712) | MODIFY(2) Frech, Levy | NOOP(2) LeBlanc, Wall | REVIEWING(2) Christey, Ozancin | Levy> The BID 1233 vulns is different from the other ones. BID 1233 uses | a FORWARD_QUERY request to overflow an in_addr structure via a memmove | in daemon/xdmcp.c, gdm_xdmcp_handle_forward_query(). In BID 1370 | a buffer is overflowed by a sprintf in xdmcp.c, send_failed(). | Frech> XF:gnome-gdm-bo(4530) | Christey> MANDRAKE:MDKSA-2001:070 | URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-070.php3 | Christey> BUGTRAQ:20000527 gdm exploit | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=96017189021021&w=2 | | Consider REDHAT:RHSA-2000:027 | Christey> RHSA-2000:027 confirmed via Mark Cox | View |
2070 | CVE-2000-0492 | Candidate | PassWD 1.2 uses weak encryption (trivial encoding) to store passwords, which allows an attacker who can read the password file to easliy decrypt the passwords. | Proposed (20000712) | ACCEPT(1) Levy | MODIFY(2) Frech, Ozancin | NOOP(2) LeBlanc, Wall | Ozancin> change "attacker who can read the password" to "attacker to decrypt and read | the password" | Frech> XF:passwd-weak-encryption(4596) | View |
2080 | CVE-2000-0503 | Candidate | The IFRAME of the WebBrowser control in Internet Explorer 5.01 allows a remote attacker to violate the cross frame security policy via the NavigateComplete2 event. | Proposed (20000712) | ACCEPT(1) Levy | MODIFY(2) Frech, Wall | NOOP(2) LeBlanc, Ozancin | REVIEWING(1) Christey | Wall> This affects more than IE 5.01. See http://www.securityfocus.com/bid/1311 for | all versions of IE that this affects. Works on Windows 98, IE 5.01 and IE 5.5. | LeBlanc> If this is the one I was discussing offline with Steve, ACCEPT | Frech> XF:ie-cross-frame(4610) | Christey> Make sure this is the one I was discussing offline with David :-) | Frech> CVE-2000-0503 was reassigned to ie-frame-domain-file-access(5504) from | ie-cross-frame(4610), which was obsoleted and redirected to this | issue. Since these are the same issues but just described differently, | CVE-2000-0503 appears to be a dupe of CVE-2000-0768. | View |
2086 | CVE-2000-0509 | Candidate | Buffer overflows in the finger and whois demonstration scripts in Sambar Server 4.3 allow remote attackers to execute arbitrary commands via a long hostname. | Proposed (20000712) | ACCEPT(2) Levy, Ozancin | MODIFY(1) Frech | NOOP(2) LeBlanc, Wall | Frech> XF:sambar-dll-bo(4592) | View |
2097 | CVE-2000-0520 | Candidate | Buffer overflow in restore program 0.4b17 and earlier in dump package allows local users to execute arbitrary commands via a long tape name. | Proposed (20000712) | ACCEPT(2) Levy, Prosser | MODIFY(1) Frech | NOOP(4) Christey, LeBlanc, Ozancin, Wall | Christey> ADDREF BUGTRAQ:20000711 MDKSA-2000:018 dump update | URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0166.html | Frech> XF:linux-restore-bo(4647) | Prosser> Add Sources: | http://www.linux-mandrake.com/en/updates/2000/MDKSA-2000-018.php3?dis=6.0 | http://www.redhat.com/support/errata/RHSA-2000-100.html | View |
Page 20584 of 20943, showing 5 records out of 104715 total, starting on record 102916, ending on 102920