CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2411  CVE-2000-0842  Candidate  The search97cgi/vtopic" in the UnixWare 7 scohelphttp webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack.  Proposed (20001018)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Magdych, Wall  Frech> XF:sco-help-view-files(5226) | Christey> What is the proper "spelling" for the SCO help HTTP server? | I"ve seen it as "SCOhelp" and "scohelphttp" and "SCO help HTTP" | Christey> XF:sco-help-view-files | Christey> typo - extra "  View
2412  CVE-2000-0843  Candidate  Buffer overflow in pam_smb and pam_ntdom pluggable authentication modules (PAM) allow remote attackers to execute arbitrary commands via a login with a long user name.  Proposed (20001018)  ACCEPT(4) Armstrong, Baker, Collins, Magdych | MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall  Magdych> ACKNOWLEDGED-BY-VENDOR | Christey> ADDREF XF:pam-authentication-bo | Frech> XF:pam-authentication-bo(5225)  View
2414  CVE-2000-0845  Candidate  kdebug daemon (kdebugd) in Digital Unix 4.0F allows remote attackers to read arbitrary files by specifying the full file name in the initialization packet.  Proposed (20001018)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Magdych, Wall  Frech> XF:du-kdebugd-write-access(5262) | Christey> This problem also allows attackers to overwrite files. | ADDREF BID:1693 | ADDREF URL:http://www.securityfocus.com/bid/1693 | ADDREF XF:du-kdebugd-write-access | ADDREF http://xforce.iss.net/static/5262.php  View
2424  CVE-2000-0855  Candidate  SunFTP build 9(1) allows remote attackers to cause a denial of service by connecting to the server and disconnecting before sending a newline.  Proposed (20001018)  ACCEPT(4) Armstrong, Baker, Cole, Collins | NOOP(1) Wall  Cole> INDEPENDENT-CONFIRMATION  View
2426  CVE-2000-0857  Candidate  The logging capability in muh 2.05d IRC server does not properly cleanse user-injected format strings, which allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed nickname.  Proposed (20001018)  ACCEPT(4) Baker, Cole, Collins, Frech | NOOP(4) Armstrong, Christey, Magdych, Wall  Cole> HAS-INDEPENDENT-CONFIRMATION | Christey> ADDREF FREEBSD:FreeBSD-SA-00:57 | CHANGE> [Magdych changed vote from REVIEWING to NOOP]  View

Page 20602 of 20943, showing 5 records out of 104715 total, starting on record 103006, ending on 103010

Actions