CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2426 | CVE-2000-0857 | Candidate | The logging capability in muh 2.05d IRC server does not properly cleanse user-injected format strings, which allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed nickname. | Proposed (20001018) | ACCEPT(4) Baker, Cole, Collins, Frech | NOOP(4) Armstrong, Christey, Magdych, Wall | Cole> HAS-INDEPENDENT-CONFIRMATION | Christey> ADDREF FREEBSD:FreeBSD-SA-00:57 | CHANGE> [Magdych changed vote from REVIEWING to NOOP] | View |
2402 | CVE-2000-0833 | Candidate | Buffer overflow in WinSMTP 1.06f and 2.X allows remote attackers to cause a denial of service via a long (1) USER or (2) HELO command. | Modified (20020222-01) | ACCEPT(5) Baker, Cole, Collins, Frech, Wall | NOOP(2) Armstrong, Magdych | Cole> HAS-INDEPENDENT-CONFIRMATION | CHANGE> [Wall changed vote from REVIEWING to ACCEPT] | View |
824 | CVE-1999-0844 | Candidate | Denial of service in MDaemon WorldClient and WebConfig services via a long URL. | Proposed (19991208) | ACCEPT(2) Baker, Stracener | MODIFY(2) Cole, Frech | NOOP(1) Armstrong | RECAST(1) Christey | REVIEWING(1) Prosser | Cole> 823 and 820 are two different vulnerabilities and should be | separated out. They are both buffer overflows but accomplish it in a | different fashion and the end exploit is different. | Frech> (RECAST?) | XF:mdaemon-worldclient-dos | XF:mdaemon-webconfig-dos | Recast request: This is really two services exhibiting the same problem. | Christey> as suggested by others. | | Also see confirmation at: | http://mdaemon.deerfield.com/helpdesk/hotfix.cfm | View |
852 | CVE-1999-0872 | Candidate | Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file. | Proposed (19991214) | MODIFY(2) Cole, Frech | NOOP(1) Baker | REJECT(3) Blake, Christey, Stracener | Cole> 611 is the mail to listed above but 759 is for the mail from and | should be listed as a separate vulenrability. | Blake> This does not appear materially different from CVE-1999-0768 | Christey> This is an apparent duplicate of CVE-1999-0768. | REDHAT:RHSA-1999:030-02 describes two issues, one of which is | CVE-1999-0768, and the other is CVE-1999-0769. | Stracener> This is a duplicate of candidate CVE-1999-0768. | Frech> XF:cron-sendmail-bo-root | Christey> BID:759 is improperly assigned to this candidate and doesn"t | even describe it. It may have been inadvertently copied | from CVE-1999-0873. | View |
4157 | CVE-2001-1353 | Candidate | ghostscript before 6.51 allows local users to read and write arbitrary files as the "lp" user via the file operator, even with -dSAFER enabled. | Modified (20050702) | ACCEPT(4) Alderson, Cole, Green, Wall | MODIFY(1) Frech | NOOP(2) Christey, Foat | REVIEWING(1) Cox | Christey> [See Mark Cox" email to me 20020617, subject "can-2001-1353"] | Frech> XF:ghostscript-dsafer-read-files(7412) | View |
Page 265 of 20943, showing 5 records out of 104715 total, starting on record 1321, ending on 1325