CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5470 | CVE-2002-1083 | Candidate | Directory traversal vulnerabilities in ezContents 1.41 and earlier allow remote attackers to cause ezContents to (1) create directories using the Maintain Images:Add New:Create Subdirectory item, or (2) list directories using the Maintain Images file listing, via .. (dot dot) sequences. | Proposed (20020830) | ACCEPT(1) Foat | NOOP(3) Cole, Cox, Wall | View | |
4191 | CVE-2001-1388 | Candidate | iptables before 1.2.4 does not accurately convert rate limits that are specified on the command line, which could allow attackers or users to generate more or less traffic than intended by the administrator. | Proposed (20020830) | ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat | Frech> XF:iptables-m-change-traffic(11117) | XF:iptables-save-files-option(7489) | View |
5215 | CVE-2002-0825 | Candidate | Buffer overflow in the DNS SRV code for nss_ldap before nss_ldap-198 allows remote attackers to cause a denial of service and possibly execute arbitrary code. | Proposed (20020830) | ACCEPT(4) Baker, Cole, Cox, Foat | NOOP(2) Christey, Wall | Christey> REDHAT:RHSA-2002:084 | Christey> REDHAT:RHSA-2002:084 | Christey> BUGTRAQ:20021013 GLSA: nss_ldap | | Need to determine if the nss_ldap-199 "read buffer overflow" | (basically an incomplete patch to this issue) should get | a different CAN. | Christey> MANDRAKE:MDKSA-2002:075 | Christey> CALDERA:CSSA-2002-058.0 | Christey> XF:nssldap-dns-query-dos(10578) | URL:http://www.iss.net/security_center/static/10578.php | BID:6130 | URL:http://www.securityfocus.com/bid/6130 | Christey> The Red Hat advisory suggests this is a format string issue, | not a buffer overflow. Also may need to mention the | pam_ldap module. | Christey> REDHAT:RHSA-2002:175 | View |
5471 | CVE-2002-1084 | Candidate | The VerifyLogin function in ezContents 1.41 and earlier does not properly halt program execution if a user fails to log in properly, which allows remote attackers to modify and view restricted information via HTTP POST requests. | Proposed (20020830) | ACCEPT(1) Foat | NOOP(3) Cole, Cox, Wall | View | |
4192 | CVE-2001-1389 | Candidate | Multiple vulnerabilities in xinetd 2.3.0 and earlier, and additional variants until 2.3.3, may allow remote attackers to cause a denial of service or execute arbitrary code, primarily via buffer overflows or improper NULL termination. | Proposed (20020830) | ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat | Frech> XF:xinetd-multiple-bo(11150) | View |
Page 20879 of 20943, showing 5 records out of 104715 total, starting on record 104391, ending on 104395