CVE List

Id CVE No. Status Description Phase Votes Comments Actions
459  CVE-1999-0461  Candidate  Versions of rpcbind including Linux, IRIX, and Wietse Venema"s rpcbind allow a remote attacker to insert and delete entries by spoofing a source address.  Proposed (19990728)  MODIFY(1) Frech | RECAST(1) Baker | REVIEWING(1) Christey  Frech> ADDREF XF:pmap-sset | Christey> CVE-1999-0195 = CVE-1999-0461 ? | If this is approved over CVE-1999-0195, make sure it gets | XF:pmap-sset | Baker> THis does appear to be a duplicate. We should accept 1999-0195, since it already has the votes and get rid of this one  View
4950  CVE-2002-0559  Candidate  Buffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allow remote attackers to cause a denial of service or execute arbitrary code via (1) a long help page request without a dadname, which overflows the resulting HTTP Location header, (2) a long HTTP request to the plsql module, (3) a long password in the HTTP Authorization, (4) a long Access Descriptor (DAD) password in the addadd form, or (5) a long cache directory name.  Proposed (20020611)  ACCEPT(3) Alderson, Baker, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> ADDREF XF:oracle-appserver-location-bo(8457)  View
1990  CVE-2000-0412  Candidate  The gnapster and knapster clients for Napster do not properly restrict access only to MP3 files, which allows remote attackers to read arbitrary files from the client by specifying the full pathname for the file.  Proposed (20000615)  ACCEPT(4) Baker, Levy, Ozancin, Stracener | MODIFY(1) Frech | NOOP(2) Cole, Prosser  Frech> ADDREF XF:knapster-view-files  View
1624  CVE-2000-0046  Candidate  Buffer overflow in ICQ 99b 1.1.1.1 client allows remote attackers to execute commands via a malformed URL within an ICQ message.  Modified (20000204-01)  ACCEPT(2) Baker, Williams | MODIFY(1) Frech  Frech> ADDREF XF:icq-url-bo  View
1655  CVE-2000-0077  Candidate  The October 1998 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the ps and grep commands.  Modified (20090302)  MODIFY(2) Baker, Frech | REVIEWING(1) Christey  Frech> ADDREF XF:hp-aserver | Christey> The Bugtraq posting does not mention specific versions. | Is October 1998 equivalent to HP-UX 10.x? | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> BID:1929 | Make sure not dupe"s with CVE-2000-0005 and CVE-20000-0078. | Baker> Was the BID reference ever added to this one?  View

Page 240 of 20943, showing 5 records out of 104715 total, starting on record 1196, ending on 1200

Actions