CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5470  CVE-2002-1083  Candidate  Directory traversal vulnerabilities in ezContents 1.41 and earlier allow remote attackers to cause ezContents to (1) create directories using the Maintain Images:Add New:Create Subdirectory item, or (2) list directories using the Maintain Images file listing, via .. (dot dot) sequences.  Proposed (20020830)  ACCEPT(1) Foat | NOOP(3) Cole, Cox, Wall    View
4191  CVE-2001-1388  Candidate  iptables before 1.2.4 does not accurately convert rate limits that are specified on the command line, which could allow attackers or users to generate more or less traffic than intended by the administrator.  Proposed (20020830)  ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat  Frech> XF:iptables-m-change-traffic(11117) | XF:iptables-save-files-option(7489)  View
5215  CVE-2002-0825  Candidate  Buffer overflow in the DNS SRV code for nss_ldap before nss_ldap-198 allows remote attackers to cause a denial of service and possibly execute arbitrary code.  Proposed (20020830)  ACCEPT(4) Baker, Cole, Cox, Foat | NOOP(2) Christey, Wall  Christey> REDHAT:RHSA-2002:084 | Christey> REDHAT:RHSA-2002:084 | Christey> BUGTRAQ:20021013 GLSA: nss_ldap | | Need to determine if the nss_ldap-199 "read buffer overflow" | (basically an incomplete patch to this issue) should get | a different CAN. | Christey> MANDRAKE:MDKSA-2002:075 | Christey> CALDERA:CSSA-2002-058.0 | Christey> XF:nssldap-dns-query-dos(10578) | URL:http://www.iss.net/security_center/static/10578.php | BID:6130 | URL:http://www.securityfocus.com/bid/6130 | Christey> The Red Hat advisory suggests this is a format string issue, | not a buffer overflow. Also may need to mention the | pam_ldap module. | Christey> REDHAT:RHSA-2002:175  View
5471  CVE-2002-1084  Candidate  The VerifyLogin function in ezContents 1.41 and earlier does not properly halt program execution if a user fails to log in properly, which allows remote attackers to modify and view restricted information via HTTP POST requests.  Proposed (20020830)  ACCEPT(1) Foat | NOOP(3) Cole, Cox, Wall    View
4192  CVE-2001-1389  Candidate  Multiple vulnerabilities in xinetd 2.3.0 and earlier, and additional variants until 2.3.3, may allow remote attackers to cause a denial of service or execute arbitrary code, primarily via buffer overflows or improper NULL termination.  Proposed (20020830)  ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat  Frech> XF:xinetd-multiple-bo(11150)  View

Page 20879 of 20943, showing 5 records out of 104715 total, starting on record 104391, ending on 104395

Actions