CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2966 | CVE-2001-0145 | Candidate | Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker to execute arbitrary commands via a malformed vCard birthday field. | Proposed (20010404) | ACCEPT(4) Baker, Balinsky, Cole, Wall | MODIFY(1) Frech | REVIEWING(3) Bishop, Christey, Ziese | Christey> In a post to Bugtraq, Joel Moses notes that this is a | duplicate of CVE-2000-0756: | http://marc.theaimsgroup.com/?l=bugtraq&m=98322714210100&w=2 | | As of this writing, it is not certain which candidate | should be preferred: the candidate that has been publicly | known longer (i.e. CVE-2000-0756), or the more "official" | candidate, which has probably been publicized more (i.e. | CVE-2001-0145). | Balinsky> It seems that this is a more specific case of | CVE-2000-0756. The reference for 2000-0756 states that there is a | buffer overflow in the birthday AND the e-mail field, as well as other | suspected fields. As this current candidate only addresses the | birthday field, it seems that there are likely different lines of code | involved. | Microsoft is not specific about what specifically the patch | addresses. It is possible that the other overflows in 2000-0756 are | still vulnerable and that the @stake group just didn"t bother to test | them. | We will not know the answer until someone retests those other | fields to see if they are still vulnerable. | If they are, then 2000-0756 might deserve being split up. | Frech> XF:outlook-vcard-dos(5175) | Christey> Consider adding BID:2459 | View |
3071 | CVE-2001-0250 | Candidate | The Web Publishing feature in Netscape Enterprise Server 4.x and earlier allows remote attackers to list arbitrary directories under the web server root via the INDEX command. | Proposed (20010404) | ACCEPT(4) Baker, Bishop, Cole, Frech | NOOP(2) Wall, Ziese | Bishop> This is a problem if the policy says it is. It may not be a security | problem in general, though. I voted accept because it may be a problem. | View |
2988 | CVE-2001-0167 | Candidate | Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long rfbConnFailed packet with a long reason string. | Proposed (20010309) | ACCEPT(2) Baker, Frech | NOOP(2) Lawler, Ziese | View | |
2992 | CVE-2001-0171 | Candidate | Buffer overflow in SlimServe HTTPd 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long GET request. | Proposed (20010309) | ACCEPT(1) Frech | NOOP(2) Christey, Ziese | REVIEWING(1) Lawler | Christey> Apparently, the original discoverer re-posted an advisory | saying that version 1.1 was also affected (everything else is | a carbon copy of the original post, so it took me a minute to | see what the deal was :-) | BUGTRAQ:20010228 DOS Vulnerability in SlimServe HTTPd | URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0509.html | View |
2993 | CVE-2001-0172 | Candidate | Buffer overflow in ReiserFS 3.5.28 in SuSE Linux allows local users to cause a denial of service and possibly execute arbitrary commands by via a long directory name. | Proposed (20010309) | ACCEPT(1) Frech | NOOP(2) Lawler, Ziese | View |
Page 306 of 20943, showing 5 records out of 104715 total, starting on record 1526, ending on 1530