CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5011  CVE-2002-0620  Candidate  Buffer overflow in the Profile Service of Microsoft Commerce Server 2000 allows remote attackers to cause the server to fail or run arbitrary code in the LocalSystem security context via an input field using an affected API.  Proposed (20020726)  ACCEPT(4) Baker, Cole, Foat, Wall | NOOP(2) Christey, Cox  Christey> XF:mscs-profile-service-bo(9423) | URL:http://www.iss.net/security_center/static/9423.php  View
5365  CVE-2002-0977  Candidate  Buffer overflow in Microsoft File Transfer Manager (FTM) ActiveX control before 4.0 allows remote attackers to execute arbitrary code via a long TS value.  Proposed (20020830)  ACCEPT(1) LeBlanc | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Cox, Foat | REVIEWING(1) Wall  Christey> XF:ms-ftm-persist-bo(9906) | URL:http://www.iss.net/security_center/static/9906.php | BID:5508 | URL:http://www.securityfocus.com/bid/5508 | | Discloser claimed bug was fixed, but I can"t find independent | acknowledgement from Microsoft. Inquiry sent to Microsoft on | November 18, 2002. They acknowledged, via email, that the | issue was fixed. | Frech> XF:ms-ftm-persist-bo(9906)  View
5366  CVE-2002-0978  Candidate  Microsoft File Transfer Manager (FTM) ActiveX control before 4.0 allows remote attackers to upload or download arbitrary files to arbitrary locations via a man-in-the-middle attack with modified TGT and TGN parameters in a call to the "Persist" function.  Proposed (20020830)  ACCEPT(2) Cole, LeBlanc | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Cox, Foat | REVIEWING(1) Wall  Christey> XF:ms-ftm-file-upload(9907) | URL:http://www.iss.net/security_center/static/9907.php | BID:5512 | URL:http://www.securityfocus.com/bid/5512 | | Discloser claimed bug was fixed, but I can"t find independent | acknowledgement from Microsoft. Inquiry sent to Microsoft on | November 18, 2002. They acknowledged, via email, that the | issue was fixed. | Frech> XF:ms-ftm-file-upload(9907)  View
4558  CVE-2002-0165  Candidate  LogWatch 2.5 allows local users to gain root privileges via a symlink attack, a different vulnerability than CVE-2002-0162.  Modified (20020817-01)  ACCEPT(4) Armstrong, Cole, Cox, Green | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall  Christey> XF:logwatch-tmp-race-condition(8652) | URL:http://www.iss.net/security_center/static/8652.php | CONFIRM:http://list.kaybee.org/archives/logwatch-announce/2002-March/000003.html | (notice how this is a different announcement than CVE-2002-0162) | Frech> XF:logwatch-tmp-race-condition(8652)  View
2298  CVE-2000-0722  Candidate  Helix GNOME Updater helix-update 0.5 and earlier allows local users to install arbitrary RPM packages by creating the /tmp/helix-install installation directory before root has begun installing packages.  Proposed (20000921)  ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall  Christey> XF:linux-update-race-condition | Frech> XF:gnome-installer-overwrite-configuration(5129)  View

Page 272 of 20943, showing 5 records out of 104715 total, starting on record 1356, ending on 1360

Actions