CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4433  CVE-2002-0039  Candidate  rpcbind in SGI IRIX 6.5 through 6.5.15f, and possibly earlier versions, allows remote attackers to cause a denial of service (crash) via malformed RPC packets with invalid lengths.  Proposed (20020502)  ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cox, Foat, Wall | RECAST(3) Baker, Christey, Levy  Christey> CVE-2002-0039 (SGI rpcbind) is the same problem as | CVE-2001-1124 (HP rpcbind). These 2 candidates need to be | merged. | Christey> Consider adding BID:4386 | Christey> XF:irix-invalid-rpc-dos(8668) | URL:http://www.iss.net/security_center/static/8668.php | BID:4386 | URL:http://www.securityfocus.com/bid/4386 | Levy> BID 4386 will be merged into BID 3400. | Frech> XF:irix-invalid-rpc-dos(8668)  View
4689  CVE-2002-0297  Candidate  Buffer overflow in ScriptEase MiniWeb Server 0.95 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL in an HTTP request.  Proposed (20020502)  MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:scriptease-long-http-dos(8236)  View
4690  CVE-2002-0298  Candidate  ScriptEase MiniWeb Server 0.95 allows remote attackers to cause a denial of service (crash) via certain HTTP GET requests containing (1) a %2e%2e (encoded dot-dot), (2) several /../ (dot dot) sequences, (3) a missing URI, or (4) several ../ in a URI that does not begin with a / (slash) character.  Proposed (20020502)  MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:scriptease-get-dos(8250)  View
4693  CVE-2002-0301  Candidate  Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSE_USER and NFUSE_PASSWORD parameters.  Proposed (20020502)  ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(4) Christey, Cox, Foat, Wall  Christey> XF:nfuse-user-information-disclosure(8257) | URL:http://www.iss.net/security_center/static/8257.php | Frech> XF:nfuse-user-information-disclosure(8257)  View
4695  CVE-2002-0303  Candidate  GroupWise 6, when using LDAP authentication and when Post Office has a blank username and password, allows attackers to gain privileges of other users by logging in without a password.  Proposed (20020502)  ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> XF:groupwise-ldap-blank-password(8244)  View

Page 20808 of 20943, showing 5 records out of 104715 total, starting on record 104036, ending on 104040

Actions