CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1501 | CVE-1999-1521 | Candidate | Computalynx CMail 2.4 and CMail 2.3 SP2 SMTP servers are vulnerable to a buffer overflow attack in the MAIL FROM command that may allow a remote attacker to execute arbitrary code on the server. | Proposed (20010912) | ACCEPT(1) Frech | NOOP(4) Christey, Cole, Foat, Wall | Christey> Remove "attack" from description and slightly rewrite. | Christey> ADDREF BUGTRAQ:19991029 Vulnerability in CMail SMTP Server Version 2.4: Remotely exploitable buffer | URL:URL:http://www.securityfocus.com/archive/1/32573 | ADDREF BUGTRAQ:19990616 C-Mail SMTP Server Remote Buffer Overflow Exploit | URL:http://online.securityfocus.com/archive/1/15524 | | Note: this last post exploits an overflow through VRFY | instead of MAIL FROM. However, CD:SF-LOC suggests merging two | issues of the same type that are in the same versions. | | ADDREF BUGTRAQ:19990526 Multiple Web Interface Security Holes | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92774425211457&w=2 | View |
4134 | CVE-2001-1330 | Candidate | Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument. | Proposed (20020502) | ACCEPT(1) Green | NOOP(4) Cole, Cox, Foat, Wall | REJECT(2) Christey, Frech | Christey> Reject this for 2 reasons: | (1) It"s a carbon copy of CVE-2001-1329 | (2) CVE-2001-1329 is a dupe of CVE-1999-0101, which means | CVE-2001-1330 is, too. | Frech> CVE-2001-1330 is the same as CVE-2001-1329 | View |
7421 | CVE-2003-0594 | Candidate | Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application. | Modified (20100819) | ACCEPT(5) Armstrong, Baker, Balinsky, Cole, Cox | MODIFY(1) Frech | NOOP(1) Wall | REVIEWING(1) Christey | Christey> REDHAT:RHSA-2004:112 | URL:http://www.redhat.com/support/errata/RHSA-2004-112.html | Frech> XF:web-browser-cookie-bypass(15424) | http://xforce.iss.net/xforce/xfdb/15424 | Cox> Addref: REDHAT:RHSA-2004:112 | Christey> REDHAT:RHSA-2004:110 | URL:http://www.redhat.com/support/errata/RHSA-2004-110.html | Balinsky> Link in References. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> Consider whether this is really a design-level problem that applies to | the interaction between any vulnerable XSS, its associated domain, and | any web browser, because browsers enforce security boundaries at the | domain level. If so, then the "%2e%2e" problem may be a red herring, | or a single attack vector of any number of vectors. | | CVE-2003-0513, CVE-2003-0514, CVE-2003-0592, CVE-2003-0593, | and CVE-2003-0594 all cover this specific issue (each for a | different browser). | Christey> HP:SSRT4722 | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108448379429944&w=2 | Christey> FEDORA:FLSA:2089 | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109900315219363&w=2 | View |
6885 | CVE-2003-0056 | Candidate | Buffer overflow in secure locate (slocate) before 2.7 allows local users to execute arbitrary code via a long (1) -c or (2) -r command line argument. | Modified (20100819) | ACCEPT(4) Armstrong, Cole, Green, Jones | NOOP(2) Christey, Cox | Christey> REDHAT:RHSA-2004:041 | URL:http://www.redhat.com/support/errata/RHSA-2004-041.html | Christey> SGI:20040201-01-U | View |
6960 | CVE-2003-0131 | Candidate | The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a allow remote attackers to perform an unauthorized RSA private key operation via a modified Bleichenbacher attack that uses a large number of SSL or TLS connections using PKCS #1 v1.5 padding that cause OpenSSL to leak information regarding the relationship between ciphertext and the associated plaintext, aka the "Klima-Pokorny-Rosa attack." | Assigned (20030313) | NOOP(1) Christey | Christey> REDHAT:RHSA-2003:205 | View |
Page 292 of 20943, showing 5 records out of 104715 total, starting on record 1456, ending on 1460