CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2202  CVE-2000-0626  Candidate  Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request.  Proposed (20000803)  ACCEPT(4) Baker, Blake, Levy, Wall | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, LeBlanc, Oliver, Ozancin | REVIEWING(1) Christey  Frech> XF:alibaba-get-dos(4934) | Christey> This is in a relatively old Nessus plugin, though the exploit | uses POST instead of GET. This was probably discovered | earlier than the references indicate. | CHANGE> [Wall changed vote from NOOP to ACCEPT] | Wall> Found by Arne Vidstrom and found in multiple sources | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> See the POST comment in | http://marc.theaimsgroup.com/?l=bugtraq&m=94182951012884&w=2 | Also see http://marc.theaimsgroup.com/?l=bugtraq&m=94191318721834&w=2 | | One poster says that a large number of sites are running | Alibaba (based on a netcraft report), but I"m not 100% | sure Netcraft"s doing a good job of identifying Alibaba | servers.  View
2205  CVE-2000-0629  Candidate  The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet.  Proposed (20000803)  ACCEPT(3) Cole, Dik, Levy | MODIFY(1) Frech | NOOP(3) Christey, LeBlanc, Wall  Frech> XF:sunjava-webadmin-bbs(5135) | Christey> Need to create/update | Dik> (through internal confirmation)  View
2221  CVE-2000-0645  Candidate  WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that does not exist, via commands such as STORE UNIQUE (STOU), STORE (STOR), or APPEND (APPE).  Proposed (20000803)  ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(3) Cole, LeBlanc, Wall  Frech> XF:wftpd-rest-dos(5004)  View
2222  CVE-2000-0646  Candidate  WFTPD and WFTPD Pro 2.41 allows remote attackers to obtain the real pathname for a file by executing a STATUS (STAT) command while the file is being transferred.  Proposed (20000803)  ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(3) Cole, LeBlanc, Wall  Frech> XF:wftpd-stat-info(5005)  View
2223  CVE-2000-0647  Candidate  WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing an MLST command before logging into the server.  Proposed (20000803)  ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(3) Cole, LeBlanc, Wall  Frech> XF:wftpd-mlst-dos(5006)  View

Page 20591 of 20943, showing 5 records out of 104715 total, starting on record 102951, ending on 102955

Actions