CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3215 | CVE-2001-0397 | Candidate | Buffer overflow in Silent Runner Collector (SRC) 1.6.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long SMTP HELO command. | Proposed (20010524) | MODIFY(1) Frech | NOOP(2) Cole, Wall | REVIEWING(1) Ziese | Frech> XF:silent-runner-helo-bo(6309) | In description, product is called SilentRunner (no space). | See http://www.silentrunner.com/index.html. | View |
4678 | CVE-2002-0286 | Candidate | The GetPassword function in function.php of SiteNews 0.10 and 0.11 allows remote attackers to gain privileges and add users by providing a non-existent user name and the MD5 checksum for an empty password to add_user.php, which causes GetPassword to produce and compare a blank password for the non-existent user. | Modified (20050526) | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | Frech> XF:sitenews-getpassword-add-users(8181) | CONFIRM:http://www.securitytracker.com/alerts/2002/Feb/100349 | 8.html | View |
890 | CVE-1999-0910 | Candidate | Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user. | Proposed (19991208) | ACCEPT(4) Baker, Ozancin, Prosser, Wall | MODIFY(2) Frech, Stracener | REJECT(1) Cole | Frech> XF:siteserver-cis-cookie-cache | Cole> Whether cookies are a vulnerbality is a debate for another time, the | question here is whether the | expiration feature is a vulnerability and I do not think it is | because the underlying concerns for this | are present even without this feature. The expiration feature does | not add any new vulenrabilities | that are not already present with cookies. | Stracener> Add Ref: MSKB Q238647 | View |
230 | CVE-1999-0231 | Candidate | Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of service and possibly remote access. | Modified (19991207-01) | ACCEPT(2) Baker, Levy | NOOP(3) Christey, Landfield, Northcutt | RECAST(1) Frech | REVIEWING(1) Ozancin | Frech> XF:slmail-vrfyexpn-overflow (for Slmail v3.2 and below) | XF:smtp-vrfy-bo (many mail packages) | Northcutt> (There is no way I will have access to these systems) | Christey> Some sources report that VRFY and EXPN are both affected. | View |
2468 | CVE-2000-0899 | Candidate | Small HTTP Server 2.01 allows remote attackers to cause a denial of service by connecting to the server and sending out multiple GET, HEAD, or POST requests and closing the connection before the server responds to the requests. | Proposed (20001219) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Armstrong, Balinsky, Cole, Wall | Frech> XF:small-http-request-dos(5523) | Balinsky> Found no data on vendor web site to support this. | http://home.lanck.net/mf/srv/index.htm | View |
Page 20857 of 20943, showing 5 records out of 104715 total, starting on record 104281, ending on 104285