CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1707  CVE-2000-0129  Candidate  Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file.  Proposed (20000208)  ACCEPT(3) Baker, Blake, Cole | MODIFY(2) Frech, Levy | NOOP(2) Armstrong, Ozancin | RECAST(1) Christey | REVIEWING(1) Wall  Frech> XF:win-shortcut-api-bo | The real problem seems to be with the Windows API call, not the Serv-U FTP | app. As the "Windows Api SHGetPathFromIDList Buffer Overflow" reference | states, [The bug can] "cause whatever handles the shortcuts to crash." | As a suggestion, rephrase the description from Windows"s context, and state | that the Serv-U FTP server is an example of an app that exhibits this | problem. | Wall> Comment: the original UssrLabs advisory does mention the SHGetPathFromIDList | buffer overflow in a Windows API and that Serv-U FTP uses this API to cause the | problem. The problem does not exist on Windows 2000. The solution seems to be | in a new release of Serv-U FTP. | Levy> BID 970 | Christey> | Reports indicate that while the vulnerable function was found in Serv-U FTP | server, the function is actually from Microsoft, and as such may affect other | applications. | XF:win-shortcut-api-bo | BID:970  View
2869  CVE-2001-0048  Candidate  The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Restore Mode Password" vulnerability.  Proposed (20010202)  ACCEPT(4) Baker, Cole, Wall, Ziese | MODIFY(1) Frech  Frech> XF:win2k-directory-service-restore-password(5936)  View
2672  CVE-2000-1105  Candidate  The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a script that remotely determines the existence of files on visiting Windows 2000 systems that have Indexing Services enabled.  Proposed (20001219)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | REVIEWING(2) Christey, Wall  Frech> XF:win2k-index-service-ixsso(5502) | Christey> ADDREF MS:MS00-098 | ADDREF XF:win2k-index-service-activex | URL:http://xforce.iss.net/static/5800.php | Add "aka the "Indexing Service File Enumeration" vulnerability" | to the description. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> DUPE CVE-2001-0245? Need to check w/Microsoft.  View
3307  CVE-2001-0490  Candidate  Buffer overflow in WINAMP 2.6x and 2.7x allows attackers to execute arbitrary code via a long string in an AIP file.  Proposed (20010524)  MODIFY(1) Frech | NOOP(4) Cole, Renaud, Wall, Ziese | REVIEWING(1) Williams  Frech> XF:winamp-aip-bo(6479)  View
1627  CVE-2000-0049  Candidate  Buffer overflow in Winamp client allows remote attackers to execute commands via a long entry in a .pls file.  Modified (20071115)  ACCEPT(2) Cole, Wall | MODIFY(2) Baker, Frech | REVIEWING(1) Christey  Frech> XF:winamp-playlist-bo | Christey> This may have been discovered earlier in: | BUGTRAQ:19990512 Buffer overflow in WinAMP 2.x | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92662988700367&w=2 | See the following for possible confirmation: | URL:http://www.winamp.com/getwinamp/newfeatures.jhtml | Wall> This vulnerability has been seen in several versions of Winamp and part of ISS | X-Force | and SecuriTeam vulnerability checks. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Baker> The old confirm url doesn"t work any more... I am not sure where we can get the old changelog/error list.  View

Page 20888 of 20943, showing 5 records out of 104715 total, starting on record 104436, ending on 104440

Actions