CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
459 | CVE-1999-0461 | Candidate | Versions of rpcbind including Linux, IRIX, and Wietse Venema"s rpcbind allow a remote attacker to insert and delete entries by spoofing a source address. | Proposed (19990728) | MODIFY(1) Frech | RECAST(1) Baker | REVIEWING(1) Christey | Frech> ADDREF XF:pmap-sset | Christey> CVE-1999-0195 = CVE-1999-0461 ? | If this is approved over CVE-1999-0195, make sure it gets | XF:pmap-sset | Baker> THis does appear to be a duplicate. We should accept 1999-0195, since it already has the votes and get rid of this one | View |
4950 | CVE-2002-0559 | Candidate | Buffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allow remote attackers to cause a denial of service or execute arbitrary code via (1) a long help page request without a dadname, which overflows the resulting HTTP Location header, (2) a long HTTP request to the plsql module, (3) a long password in the HTTP Authorization, (4) a long Access Descriptor (DAD) password in the addadd form, or (5) a long cache directory name. | Proposed (20020611) | ACCEPT(3) Alderson, Baker, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | Frech> ADDREF XF:oracle-appserver-location-bo(8457) | View |
1990 | CVE-2000-0412 | Candidate | The gnapster and knapster clients for Napster do not properly restrict access only to MP3 files, which allows remote attackers to read arbitrary files from the client by specifying the full pathname for the file. | Proposed (20000615) | ACCEPT(4) Baker, Levy, Ozancin, Stracener | MODIFY(1) Frech | NOOP(2) Cole, Prosser | Frech> ADDREF XF:knapster-view-files | View |
1624 | CVE-2000-0046 | Candidate | Buffer overflow in ICQ 99b 1.1.1.1 client allows remote attackers to execute commands via a malformed URL within an ICQ message. | Modified (20000204-01) | ACCEPT(2) Baker, Williams | MODIFY(1) Frech | Frech> ADDREF XF:icq-url-bo | View |
1655 | CVE-2000-0077 | Candidate | The October 1998 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the ps and grep commands. | Modified (20090302) | MODIFY(2) Baker, Frech | REVIEWING(1) Christey | Frech> ADDREF XF:hp-aserver | Christey> The Bugtraq posting does not mention specific versions. | Is October 1998 equivalent to HP-UX 10.x? | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> BID:1929 | Make sure not dupe"s with CVE-2000-0005 and CVE-20000-0078. | Baker> Was the BID reference ever added to this one? | View |
Page 240 of 20943, showing 5 records out of 104715 total, starting on record 1196, ending on 1200