CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5067 | CVE-2002-0677 | Candidate | CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure. | Modified (20071129) | ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(1) Frech | NOOP(3) Christey, Cox, Foat | Christey> XF:tooltalk-ttdbserverd-ttisclose-validation(9526) | URL:http://www.iss.net/security_center/static/9526.php | BID:5082 | URL:http://www.securityfocus.com/bid/5082 | | HP:HPSBUX0207-199 | URL:http://archives.neohapsis.com/archives/hp/2002-q3/0011.html | Note: while the HP advisory discusses "buffer overflows," | it specifically mentions CA-2002-20, and the text of the | advisory is included in vendor statements for the CERT-VU"s for both | ToolTalk issues covered by CA-2002-20. | | AIXAPAR:IY32368 | URL:http://archives.neohapsis.com/archives/aix/2002-q3/0002.html | AIXAPAR:IY32370 | URL:http://archives.neohapsis.com/archives/aix/2002-q3/0002.html | Christey> HP:HPSBUX0207-199 | URL:http://online.securityfocus.com/advisories/4290 | Christey> SGI:20021101-01-P | Christey> Sun confirmed via email to Matt Wojcik (of MITRE"s OVAL | project) that Sun alert 46022 also addresses this issue. | Frech> XF:tooltalk-ttdbserverd-ttisclose-validation(9526) | View |
4752 | CVE-2002-0360 | Candidate | Buffer overflow in Sun AnswerBook2 1.4 through 1.4.3 allows remote attackers to execute arbitrary code via a long filename argument to the gettransbitmap CGI program. | Modified (20040725) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall | Christey> XF:sun-answerbook2-gettransbitmap-bo(9117) | URL:http://www.iss.net/security_center/static/9117.php | BID:4784 | URL:http://www.securityfocus.com/bid/4784 | Frech> XF:sun-answerbook2-gettransbitmap-bo(9117) | View |
5919 | CVE-2002-1535 | Candidate | Secure Webserver 1.1 in Raptor 6.5 and Symantec Enterprise Firewall 6.5.2 allows remote attackers to identify IP addresses of hosts on the internal network via a CONNECT request, which generates different error messages if the host is present. | Modified (20071016) | ACCEPT(2) Armstrong, Baker | NOOP(4) Christey, Cole, Cox, Wall | Christey> XF:simple-webserver-topology-disclosure(10363) | URL:http://www.iss.net/security_center/static/10363.php | CONFIRM:http://securityresponse.symantec.com/avcenter/security/Content/2002.10.11a.html | View |
4591 | CVE-2002-0199 | Candidate | Buffer overflow in admin.cgi for Nullsoft Shoutcast Server 1.8.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an argument with a large number of backslashes. | Proposed (20020502) | ACCEPT(1) Green | NOOP(4) Christey, Cole, Foat, Wall | Christey> XF:shoutcast-admin-cgi-dos(7958) | URL:http://xforce.iss.net/static/7958.php | View |
2360 | CVE-2000-0784 | Candidate | sshd program in the Rapidstream 2.1 Beta VPN appliance has a hard-coded "rsadmin" account with a null password, which allows remote attackers to execute arbitrary commands via ssh. | Proposed (20000921) | ACCEPT(3) Baker, Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall | Christey> XF:rapidstream-remote-execution | http://xforce.iss.net/static/5093.php | Frech> XF:rapidstream-remote-execution(5093) | View |
Page 269 of 20943, showing 5 records out of 104715 total, starting on record 1341, ending on 1345