CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5111  CVE-2002-0721  Candidate  Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.  Modified (20071101)  ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(2) Foat, Frech | NOOP(2) Christey, Cox  Foat> The description should list MSDE 1.0 and MSDE 2000 as acknowledged by | Microsoft. | Christey> CERT-VN:VU#818939 | URL:http://www.kb.cert.org/vuls/id/818939 | CERT-VN:VU#939675 | URL:http://www.kb.cert.org/vuls/id/939675 | CERT-VN:VU#399531 | URL:http://www.kb.cert.org/vuls/id/399531 | BID:5481 | URL:http://www.securityfocus.com/bid/5481 | XF:mssql-xp-weak-permissions(9857) | URL:http://www.iss.net/security_center/static/9857.php | Frech> XF:mssql-xp-weak-permissions(9857)  View
5089  CVE-2002-0699  Candidate  Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user"s system via HTML.  Modified (20061101)  ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(2) Foat, Frech | NOOP(2) Christey, Cox  Foat> Replace the word "Unknown" with "A" and change "allow" to "allows". | Christey> The "Unknown" portion of the vulnerability statement is used | to emphasize that the vendor has not provided sufficient | information to understand the cause or nature of the problem. | This is important because this vagueness makes it difficult | or impossible to resolve it with vulnerability reports | from other sources, increasing the risk of duplication. | | Most candidates affected by CD:VAGUE will use this description | style. | Christey> XF:win-certificate-enrollment-dos(9982) | URL:http://www.iss.net/security_center/static/9982.php | BID:5593 | URL:http://www.securityfocus.com/bid/5593 | Frech> XF:win-certificate-enrollment-dos(9982)  View
4503  CVE-2002-0109  Candidate  Linksys EtherFast BEFN2PS4, BEFSR41, and BEFSR81 Routers, and possibly other products, allow remote attackers to gain sensitive information and cause a denial of service via an SNMP query for the default community string "public," which causes the router to change its configuration and send SNMP trap information back to the system that initiated the query.  Proposed (20020315)  ACCEPT(2) Frech, Green | MODIFY(1) Foat | NOOP(2) Cole, Wall  Foat> Our testing showed that this vulnerabiltiy did not apply to BEFSR41 | routers.  View
5209  CVE-2002-0819  Candidate  Format string vulnerability in artsd, when called by artswrapper, allows local users to gain privileges via format strings in the -a argument, which results in an error message that is not properly handled in a call to the arts_fatal function.  Proposed (20020830)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Cole, Cox, Wall | REJECT(1) Foat  Foat> Artsd was supposedly vulnerable to a format string vulneraibity | resulting in elevated privileges because it called command (artscontrol) and was | installed suid root. The problem was supposed to affect Red Hat 7.2. We looked | at two different install of 7.2, neither of which had artsd nor artscontrol | installed suid root. | Frech> XF:artswrapper-artsd-format-string(9813)  View
2764  CVE-2000-1197  Candidate  POP2 or POP3 server (pop3d) in imap-uw IMAP package on FreeBSD and other operating systems creates lock files with predictable names, which allows local users to cause a denial of service (lack of mail access) for other users by creating lock files for other mail boxes.  Proposed (20010912)  ACCEPT(4) Baker, Cole, Foat, Stracener | MODIFY(1) Frech | NOOP(1) Wall  Foat> ACKNOWLEDGED-BY-VENDOR | Frech> XF:freebsd-imap-uw(4335) | Frech> Please change XF:freebsd-imap-uw(4335) to XF:pop-predictable-lockfile(4335)  View

Page 247 of 20943, showing 5 records out of 104715 total, starting on record 1231, ending on 1235

Actions