CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
7642 | CVE-2003-0818 | Candidate | Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings. | Modified (20061101) | ACCEPT(4) Armstrong, Baker, Cole, Wall | NOOP(2) Christey, Cox | Christey> Various sources say that Windows Server 2003 is also affected. | | XF:win-asn1-library-bo(15039) | URL:http://xforce.iss.net/xforce/xfdb/15039 | BID:9633 | URL:http://www.securityfocus.com/bid/9633 | EEYE:AD20040210-2 | URL:http://www.eeye.com/html/Research/Advisories/AD20040210-2.html | View |
3816 | CVE-2001-1012 | Candidate | Vulnerability in screen before 3.9.10, related to a multi-attach error, allows local users to gain root privileges when there is a subdirectory under /tmp/screens/. | Modified (20020817-01) | ACCEPT(2) Frech, Green | NOOP(4) Christey, Cole, Foat, Wall | Christey> Typo: "toa" | View |
5410 | CVE-2002-1022 | Candidate | BadBlue server stores passwords in plaintext in the ext.ini file, which could allow local and possibly remote attackers to gain privileges. | Modified (20050628) | ACCEPT(2) Foat, Frech | NOOP(4) Christey, Cole, Cox, Wall | Christey> typo: "nad" (amazing that"s the only typo for "and" at this | time!) | View |
3928 | CVE-2001-1124 | Candidate | rpcbind in HP-UX 11.00, 11.04 and 11.11 allows remote attackers to cause a denial of service (core dump) via a malformed RPC portmap requests, possibly related to a buffer overflow. | Modified (20090302) | ACCEPT(4) Cole, Frech, Green, Ziese | NOOP(3) Armstrong, Foat, Wall | RECAST(2) Baker, Christey | Christey> typo: "a malformed RPC portmap requests" | CHANGE> [Christey changed vote from NOOP to RECAST] | Christey> CVE-2002-0039 (SGI rpcbind) is the same problem as | CVE-2001-1124 (HP rpcbind). These 2 candidates need to be | merged. | Baker> MERGE with CVE-2002-0039 | View |
1826 | CVE-2000-0248 | Candidate | The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password that allows remote attackers to execute arbitrary commands. | Modified (20070924) | ACCEPT(3) Baker, Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall | REJECT(1) Cox | Christey> Typo fix: change "passowrd" to "password" | ADDREF BID:1148 | ADDREF URL:http://www.securityfocus.com/bid/1148 | Christey> ADDREF XF:piranha-default-password | Frech> XF:piranha-default-password | In description, passowrd should be password. | Cox> The "execute arbitrary commands" part is a seperate vulnerability, | already assigned CVE-2000-0322. The package was designed to have no | password on installation, so "backdoor" does not apply. When users | install Piranha they are expected to add a password to the web | administration GUI, it"s a documented part of the procedure. "The web | GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux | Piranha package installs with a default password" is accurate if it | qualifies as an exposure. | Christey> BUGTRAQ:20000425 piranha default password/exploit | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95668829621268&w=2 | | Default accounts/passwords need to be accounted for in CVE, | but the question is what level of abstraction to use - a | separate CVE for each password, or one CVE for all passwords, | or somewhere in the middle? That is the crux of CD:CF-PASS. | View |
Page 280 of 20943, showing 5 records out of 104715 total, starting on record 1396, ending on 1400