CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4433 | CVE-2002-0039 | Candidate | rpcbind in SGI IRIX 6.5 through 6.5.15f, and possibly earlier versions, allows remote attackers to cause a denial of service (crash) via malformed RPC packets with invalid lengths. | Proposed (20020502) | ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cox, Foat, Wall | RECAST(3) Baker, Christey, Levy | Christey> CVE-2002-0039 (SGI rpcbind) is the same problem as | CVE-2001-1124 (HP rpcbind). These 2 candidates need to be | merged. | Christey> Consider adding BID:4386 | Christey> XF:irix-invalid-rpc-dos(8668) | URL:http://www.iss.net/security_center/static/8668.php | BID:4386 | URL:http://www.securityfocus.com/bid/4386 | Levy> BID 4386 will be merged into BID 3400. | Frech> XF:irix-invalid-rpc-dos(8668) | View |
4689 | CVE-2002-0297 | Candidate | Buffer overflow in ScriptEase MiniWeb Server 0.95 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL in an HTTP request. | Proposed (20020502) | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | Frech> XF:scriptease-long-http-dos(8236) | View |
4690 | CVE-2002-0298 | Candidate | ScriptEase MiniWeb Server 0.95 allows remote attackers to cause a denial of service (crash) via certain HTTP GET requests containing (1) a %2e%2e (encoded dot-dot), (2) several /../ (dot dot) sequences, (3) a missing URI, or (4) several ../ in a URI that does not begin with a / (slash) character. | Proposed (20020502) | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | Frech> XF:scriptease-get-dos(8250) | View |
4693 | CVE-2002-0301 | Candidate | Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSE_USER and NFUSE_PASSWORD parameters. | Proposed (20020502) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(4) Christey, Cox, Foat, Wall | Christey> XF:nfuse-user-information-disclosure(8257) | URL:http://www.iss.net/security_center/static/8257.php | Frech> XF:nfuse-user-information-disclosure(8257) | View |
4695 | CVE-2002-0303 | Candidate | GroupWise 6, when using LDAP authentication and when Post Office has a blank username and password, allows attackers to gain privileges of other users by logging in without a password. | Proposed (20020502) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | Frech> XF:groupwise-ldap-blank-password(8244) | View |
Page 20808 of 20943, showing 5 records out of 104715 total, starting on record 104036, ending on 104040