CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2202 | CVE-2000-0626 | Candidate | Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request. | Proposed (20000803) | ACCEPT(4) Baker, Blake, Levy, Wall | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, LeBlanc, Oliver, Ozancin | REVIEWING(1) Christey | Frech> XF:alibaba-get-dos(4934) | Christey> This is in a relatively old Nessus plugin, though the exploit | uses POST instead of GET. This was probably discovered | earlier than the references indicate. | CHANGE> [Wall changed vote from NOOP to ACCEPT] | Wall> Found by Arne Vidstrom and found in multiple sources | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> See the POST comment in | http://marc.theaimsgroup.com/?l=bugtraq&m=94182951012884&w=2 | Also see http://marc.theaimsgroup.com/?l=bugtraq&m=94191318721834&w=2 | | One poster says that a large number of sites are running | Alibaba (based on a netcraft report), but I"m not 100% | sure Netcraft"s doing a good job of identifying Alibaba | servers. | View |
2205 | CVE-2000-0629 | Candidate | The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet. | Proposed (20000803) | ACCEPT(3) Cole, Dik, Levy | MODIFY(1) Frech | NOOP(3) Christey, LeBlanc, Wall | Frech> XF:sunjava-webadmin-bbs(5135) | Christey> Need to create/update | Dik> (through internal confirmation) | View |
2221 | CVE-2000-0645 | Candidate | WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that does not exist, via commands such as STORE UNIQUE (STOU), STORE (STOR), or APPEND (APPE). | Proposed (20000803) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(3) Cole, LeBlanc, Wall | Frech> XF:wftpd-rest-dos(5004) | View |
2222 | CVE-2000-0646 | Candidate | WFTPD and WFTPD Pro 2.41 allows remote attackers to obtain the real pathname for a file by executing a STATUS (STAT) command while the file is being transferred. | Proposed (20000803) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(3) Cole, LeBlanc, Wall | Frech> XF:wftpd-stat-info(5005) | View |
2223 | CVE-2000-0647 | Candidate | WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing an MLST command before logging into the server. | Proposed (20000803) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(3) Cole, LeBlanc, Wall | Frech> XF:wftpd-mlst-dos(5006) | View |
Page 20591 of 20943, showing 5 records out of 104715 total, starting on record 102951, ending on 102955