CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4808 | CVE-2002-0416 | Candidate | Buffer overflow in SH39 MailServer 1.21 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long command to the SMTP port. | Proposed (20020611) | ACCEPT(2) Alderson, Frech | NOOP(4) Cole, Cox, Foat, Wall | Frech> Article title for BUGTRAQ:20020305 is "Buffer Overflows in | sh39.com"s mailserver 1.21". | View |
241 | CVE-1999-0242 | Candidate | Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords. | Modified (20000106-01) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Christey, Northcutt, Shostack, Wall | REVIEWING(1) Levy | Frech> Ambiguous description: need more detail. Possibly: | XF:linux-pop3d (mktemp() leads to reading e-mail) | Christey> At first glance this might look like CVE-1999-0123 or | CVE-1999-0125, however this particular candidate arises out | of a brief mention of the problem in a larger posting which | discusses CVE-1999-0123 (which may be the same bug as | CVE-1999-0125). See the following phrase in the Bugtraq | post: "one such example of this is in.pop3d" | | However, the original source of this candidate"s description | explicitly mentions shadowed passwords, though it has no | references to help out here. | View |
240 | CVE-1999-0241 | Candidate | Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm. | Modified (19990925-01) | ACCEPT(3) Hill, Northcutt, Proctor | MODIFY(2) Frech, Prosser | NOOP(1) Baker | REVIEWING(1) Christey | Frech> Also add to references: | XF:sol-mkcookie | Prosser> additional source | Bugtraq | "X11 cookie hijacker" | http://www.securityfocus.com | Christey> The cookie hijacker thread has to do with stealing cookies | through a file with bad permissions. I"m not sure the | X-Force reference identifies this problem either. | Christey> CIAC:G-04 | URL:http://ciac.llnl.gov/ciac/bulletins/g-04.shtml | SGI:19960601-01-I | URL:ftp://patches.sgi.com/support/free/security/advisories/19960601-01-I | CERT:VB-95:08 | View |
4518 | CVE-2002-0124 | Candidate | MDG Computer Services Web Server 4D/eCommerce 3.5.3 allows remote attackers to exploit directory traversal vulnerability via a ../ (dot dot) containing URL-encoded slashes in the HTTP request. | Proposed (20020315) | ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall | Frech> ADDREF:http://www.mdg.com/(MDG Web site) | View |
443 | CVE-1999-0444 | Candidate | Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files. | Modified (20000106-01) | ACCEPT(1) Baker | MODIFY(1) Frech | Frech> ADDREF: XF:windows-arp-dos | View |
Page 239 of 20943, showing 5 records out of 104715 total, starting on record 1191, ending on 1195