CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1765  CVE-2000-0187  Candidate  EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.  Proposed (20000322)  ACCEPT(2) Levy, Ozancin | MODIFY(1) Frech | NOOP(6) Baker, Blake, Christey, Cole, LeBlanc, Wall  Christey> Since EZShopper is written in Perl, there is strong evidence | that both the .. and metacharacter attack probably go | through the same insecure open() call. (Perl"s open can | either read a regular file, or read piped output from | a command that is specified to the open). | Frech> XF:ezshopper-loadpage-cgi(4044)  View
893  CVE-1999-0913  Candidate  dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters.  Proposed (19991214)  ACCEPT(2) Blake, Stracener | MODIFY(1) Frech | NOOP(4) Armstrong, Baker, Cole, LeBlanc | REVIEWING(1) Christey  Christey> Some voters should use ABSTAIN. | Frech> XF:dragon-fire-ids-metachar(3834) | CHANGE> [Armstrong changed vote from REVIEWING to NOOP]  View
5360  CVE-2002-0972  Candidate  Buffer overflows in PostgreSQL 7.2 allow attackers to cause a denial of service and possibly execute arbitrary code via long arguments to the functions (1) lpad or (2) rpad.  Modified (20071113)  MODIFY(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall  Christey> SUSE:SuSE-SA:2002:039 | Christey> There are numerous PostgreSQL issues that were reported around | the same time frame. Need to make sure that they are all | properly identified. | Christey> CONFIRM:http://marc.theaimsgroup.com/?l=postgresql-announce&m=103062536330644 | CONFIRM:http://archives.postgresql.org/pgsql-announce/2002-08/msg00004.php | CONECTIVA:CLA-2002:524 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000524 | SUSE:SuSE-SA:2002:038 | URL:http://www.suse.de/de/security/2002_038_postgresql.html | BUGTRAQ:20020826 GLSA: PostgreSQL | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=103036987114437&w=2 | BUGTRAQ:20020824 Fwd: [GENERAL] PostgreSQL 7.2.2: Security Release | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=103021186622725&w=2 | Christey> MANDRAKE:MDKSA-2002:062 | URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2002:062 | REDHAT:RHSA-2003:015 | URL:http://www.redhat.com/support/errata/RHSA-2003-015.html | Frech> XF:postgresql-lpad-rpad-bo(9927) | Christey> REDHAT:RHSA-2003:010  View
6928  CVE-2003-0099  Candidate  Multiple buffer overflows in apcupsd before 3.8.6, and 3.10.x before 3.10.5, may allow attackers to cause a denial of service or execute arbitrary code, related to usage of the vsprintf function.  Modified (20071016)  ACCEPT(4) Armstrong, Cole, Green, Jones | NOOP(2) Christey, Cox  Christey> SUSE:SuSE-SA:2003:022 | CALDERA:CSSA-2003-015.0 | Christey> DEBIAN:DSA-277 | URL:http://www.debian.org/security/2003/dsa-277 | Christey> As observed in an email to us by a third party, it appears | that 3.8.6 is probably not affected by this, so the | description should be changed to refer to "3.10.x before | 3.10.5, and 3.8.x before 3.8.6". | Christey> An email from Kern Sibbald on August 21, 2003, confirmed that | 3.8.6 and 3.10.5 fixed the issue. | | CONFIRM:http://sourceforge.net/project/shownotes.php?release_id=137892  View
6927  CVE-2003-0098  Candidate  Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server.  Modified (20071016)  ACCEPT(4) Armstrong, Cole, Green, Jones | NOOP(2) Christey, Cox  Christey> SUSE:SuSE-SA:2003:022 | CALDERA:CSSA-2003-015.0 | Christey> DEBIAN:DSA-277 | URL:http://www.debian.org/security/2003/dsa-277 | Christey> CHANGEREF BID:6828 | (BID:7200 is for the overflows)  View

Page 20655 of 20943, showing 5 records out of 104715 total, starting on record 103271, ending on 103275

Actions