CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3228 | CVE-2001-0410 | Candidate | Buffer overflow in Trend Micro Virus Buster 2001 8.02 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long "From" header. | Proposed (20010524) | MODIFY(1) Frech | NOOP(2) Cole, Wall | REVIEWING(1) Ziese | Frech> XF:virusbuster-mua-bo(6034) | Possible | CONFIRM:http://www.securityfocus.com/archive/1/173231, but Trend URL | in message was currently down. | Possible close-match or duplicate with CVE-2001-0174 (most likely | this is a level-of-abstraction issue). | View |
3229 | CVE-2001-0411 | Candidate | Reliant Unix 5.44 and earlier allows remote attackers to cause a denial of service via an ICMP port unreachable packet, which causes Reliant to drop all connections to the source address of the packet. | Proposed (20010524) | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REJECT(1) Meunier | Frech> XF:reliant-unix-ppd-symlink(6408) | Frech> Change to reliant-unix-icmp-dos(6646) | Christey> (prompted from Pascal Meunier) should this be treated | as a general design issue with ICMP? Or is it a specific | implementation flaw that only affects Reliant? | Meunier> lower level (more precise) duplicate or sub-class of high | level description CVE-1999-0214 | View |
3233 | CVE-2001-0415 | Candidate | REDIPlus program, REDI.exe, stores passwords and user names in cleartext in the StartLog.txt log file, which allows local users to gain access to other accounts. | Proposed (20010524) | ACCEPT(2) Cole, Frech | NOOP(3) Oliver, Wall, Ziese | View | |
3235 | CVE-2001-0417 | Candidate | Kerberos 4 (aka krb4) allows local users to overwrite arbitrary files via a symlink attack on new ticket files. | Proposed (20010524) | ACCEPT(3) Baker, Cole, Ziese | NOOP(1) Wall | REJECT(3) Christey, Frech, Oliver | Frech> DUPLICATE OF CVE-2001-0036: KTH Kerberos IV allows local users to | overwrite arbitrary files via a symlink attack on a ticket file. | Oliver> Appears to be a subset of CVE-2001-036. | Christey> Change description to point out that the Kerberos 5 package is | affected. | FREEBSD:FreeBSD-SA-01:25 | Also ensure that the other problems described in the FreeBSD | advisory have CANs/CVEs. | CHANGE> [Christey changed vote from NOOP to REJECT] | Christey> Agree that these are dupes. Since CVE-2001-0036 is already | an official CVE entry, this candidate will be rejected. | This CAN"s references will be added to CVE-2001-0036. | View |
3236 | CVE-2001-0418 | Candidate | content.pl script in NCM Content Management System allows remote attackers to read arbitrary contents of the content database by inserting SQL characters into the id parameter. | Proposed (20010524) | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Williams | Frech> XF:ncm-content-database-access(6386) | View |
Page 20652 of 20943, showing 5 records out of 104715 total, starting on record 103256, ending on 103260