CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4808  CVE-2002-0416  Candidate  Buffer overflow in SH39 MailServer 1.21 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long command to the SMTP port.  Proposed (20020611)  ACCEPT(2) Alderson, Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> Article title for BUGTRAQ:20020305 is "Buffer Overflows in | sh39.com"s mailserver 1.21".  View
241  CVE-1999-0242  Candidate  Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords.  Modified (20000106-01)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Christey, Northcutt, Shostack, Wall | REVIEWING(1) Levy  Frech> Ambiguous description: need more detail. Possibly: | XF:linux-pop3d (mktemp() leads to reading e-mail) | Christey> At first glance this might look like CVE-1999-0123 or | CVE-1999-0125, however this particular candidate arises out | of a brief mention of the problem in a larger posting which | discusses CVE-1999-0123 (which may be the same bug as | CVE-1999-0125). See the following phrase in the Bugtraq | post: "one such example of this is in.pop3d" | | However, the original source of this candidate"s description | explicitly mentions shadowed passwords, though it has no | references to help out here.  View
240  CVE-1999-0241  Candidate  Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm.  Modified (19990925-01)  ACCEPT(3) Hill, Northcutt, Proctor | MODIFY(2) Frech, Prosser | NOOP(1) Baker | REVIEWING(1) Christey  Frech> Also add to references: | XF:sol-mkcookie | Prosser> additional source | Bugtraq | "X11 cookie hijacker" | http://www.securityfocus.com | Christey> The cookie hijacker thread has to do with stealing cookies | through a file with bad permissions. I"m not sure the | X-Force reference identifies this problem either. | Christey> CIAC:G-04 | URL:http://ciac.llnl.gov/ciac/bulletins/g-04.shtml | SGI:19960601-01-I | URL:ftp://patches.sgi.com/support/free/security/advisories/19960601-01-I | CERT:VB-95:08  View
4518  CVE-2002-0124  Candidate  MDG Computer Services Web Server 4D/eCommerce 3.5.3 allows remote attackers to exploit directory traversal vulnerability via a ../ (dot dot) containing URL-encoded slashes in the HTTP request.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall  Frech> ADDREF:http://www.mdg.com/(MDG Web site)  View
443  CVE-1999-0444  Candidate  Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files.  Modified (20000106-01)  ACCEPT(1) Baker | MODIFY(1) Frech  Frech> ADDREF: XF:windows-arp-dos  View

Page 239 of 20943, showing 5 records out of 104715 total, starting on record 1191, ending on 1195

Actions