CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3228  CVE-2001-0410  Candidate  Buffer overflow in Trend Micro Virus Buster 2001 8.02 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long "From" header.  Proposed (20010524)  MODIFY(1) Frech | NOOP(2) Cole, Wall | REVIEWING(1) Ziese  Frech> XF:virusbuster-mua-bo(6034) | Possible | CONFIRM:http://www.securityfocus.com/archive/1/173231, but Trend URL | in message was currently down. | Possible close-match or duplicate with CVE-2001-0174 (most likely | this is a level-of-abstraction issue).  View
3229  CVE-2001-0411  Candidate  Reliant Unix 5.44 and earlier allows remote attackers to cause a denial of service via an ICMP port unreachable packet, which causes Reliant to drop all connections to the source address of the packet.  Proposed (20010524)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REJECT(1) Meunier  Frech> XF:reliant-unix-ppd-symlink(6408) | Frech> Change to reliant-unix-icmp-dos(6646) | Christey> (prompted from Pascal Meunier) should this be treated | as a general design issue with ICMP? Or is it a specific | implementation flaw that only affects Reliant? | Meunier> lower level (more precise) duplicate or sub-class of high | level description CVE-1999-0214  View
3233  CVE-2001-0415  Candidate  REDIPlus program, REDI.exe, stores passwords and user names in cleartext in the StartLog.txt log file, which allows local users to gain access to other accounts.  Proposed (20010524)  ACCEPT(2) Cole, Frech | NOOP(3) Oliver, Wall, Ziese    View
3235  CVE-2001-0417  Candidate  Kerberos 4 (aka krb4) allows local users to overwrite arbitrary files via a symlink attack on new ticket files.  Proposed (20010524)  ACCEPT(3) Baker, Cole, Ziese | NOOP(1) Wall | REJECT(3) Christey, Frech, Oliver  Frech> DUPLICATE OF CVE-2001-0036: KTH Kerberos IV allows local users to | overwrite arbitrary files via a symlink attack on a ticket file. | Oliver> Appears to be a subset of CVE-2001-036. | Christey> Change description to point out that the Kerberos 5 package is | affected. | FREEBSD:FreeBSD-SA-01:25 | Also ensure that the other problems described in the FreeBSD | advisory have CANs/CVEs. | CHANGE> [Christey changed vote from NOOP to REJECT] | Christey> Agree that these are dupes. Since CVE-2001-0036 is already | an official CVE entry, this candidate will be rejected. | This CAN"s references will be added to CVE-2001-0036.  View
3236  CVE-2001-0418  Candidate  content.pl script in NCM Content Management System allows remote attackers to read arbitrary contents of the content database by inserting SQL characters into the id parameter.  Proposed (20010524)  MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Williams  Frech> XF:ncm-content-database-access(6386)  View

Page 20652 of 20943, showing 5 records out of 104715 total, starting on record 103256, ending on 103260

Actions