CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8688  CVE-2004-0260  Candidate  The AddToMailingList function in CactuSoft CactuShop 5.0 Lite contains a backdoor that allows remote attackers to delete arbitrary files via an email address that starts with |||.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8703  CVE-2004-0275  Candidate  SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
1595  CVE-2000-0017  Candidate  Buffer overflow in Linux linuxconf package allows remote attackers to gain root privileges via a long parameter.  Proposed (20000111)  NOOP(4) Armstrong, Baker, Christey, Stracener | REJECT(2) Frech, Levy  Christey> It"s not certain whether this is exploitable or not. An | expert (the linuxconf author?) wasn"t able to duplicate the | bug - see http://lwn.net/1999/1223/a/linuxconfresponse.html | | The original posting with example exploit was | http://marc.theaimsgroup.com/?l=bugtraq&m=94580196627059&w=2 | | However - GIAC and the Security Focus incidents list have | consistently reported that scans are taking place for | linuxconf, so do the hackers know more than we do? | Frech> Unless vendor or other confirmation occurs, there has been no corroboration | of this issue in public forums. | CHANGE> [Armstrong changed vote from ACCEPT to NOOP]  View
3121  CVE-2001-0300  Candidate  oidldapd 2.1.1.1 in Oracle 8.1.7 records log files in a directory (ldaplog) that has world-writable permissions, which may allow local users to delete logs and/or overwrite other files via a symlink attack.  Modified (20050509)  NOOP(3) Cole, Wall, Ziese | REJECT(1) Frech | REVIEWING(1) Bishop  Frech> Validity threshold is not met by the references cited. Would | be willing to reassess and change vote if more information is | forthcoming.  View
1541  CVE-1999-1561  Candidate  Nullsoft SHOUTcast server stores the administrative password in plaintext in a configuration file (sc_serv.conf), which could allow a local user to gain administrative privileges on the server.  Proposed (20010912)  NOOP(3) Cole, Foat, Wall | REVIEWING(1) Frech  Frech> (ACCEPT; Task 2359)  View

Page 24 of 20943, showing 5 records out of 104715 total, starting on record 116, ending on 120

Actions