CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2069  CVE-2000-0491  Candidate  Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY request.  Proposed (20000712)  MODIFY(2) Frech, Levy | NOOP(2) LeBlanc, Wall | REVIEWING(2) Christey, Ozancin  Levy> The BID 1233 vulns is different from the other ones. BID 1233 uses | a FORWARD_QUERY request to overflow an in_addr structure via a memmove | in daemon/xdmcp.c, gdm_xdmcp_handle_forward_query(). In BID 1370 | a buffer is overflowed by a sprintf in xdmcp.c, send_failed(). | Frech> XF:gnome-gdm-bo(4530) | Christey> MANDRAKE:MDKSA-2001:070 | URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-070.php3 | Christey> BUGTRAQ:20000527 gdm exploit | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=96017189021021&w=2 | | Consider REDHAT:RHSA-2000:027 | Christey> RHSA-2000:027 confirmed via Mark Cox  View
2266  CVE-2000-0690  Candidate  Auction Weaver CGI script 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the fromfile parameter.  Proposed (20000921)  ACCEPT(1) Baker | MODIFY(2) Frech, Levy | NOOP(3) Christey, Cole, Wall  Levy> Reference: BID 1645 | Christey> BID:1645 | URL:http://www.securityfocus.com/bid/1645 | Frech> XF:auction-weaver-execute-commands(6175)  View
1963  CVE-2000-0385  Candidate  FileMaker Pro 5 Web Companion allows remote attackers to bypass Field-Level database security restrictions via the XML publishing or email capabilities.  Proposed (20000615)  ACCEPT(5) Baker, Frech, Ozancin, Prosser, Stracener | MODIFY(1) Levy | NOOP(1) Cole  Levy> Reference: BID 1159  View
1964  CVE-2000-0386  Candidate  FileMaker Pro 5 Web Companion allows remote attackers to send anonymous or forged email.  Proposed (20000615)  ACCEPT(5) Baker, Frech, Ozancin, Prosser, Stracener | MODIFY(1) Levy | NOOP(1) Cole  Levy> Reference: BID 1159  View
2007  CVE-2000-0429  Candidate  A backdoor password in Cart32 3.0 and earlier allows remote attackers to execute arbitrary commands.  Proposed (20000615)  ACCEPT(3) Ozancin, Prosser, Stracener | MODIFY(2) Frech, Levy | NOOP(2) Baker, Cole  Levy> Reference: BID 1153 | Frech> XF:cart32-admin-password  View

Page 31 of 20943, showing 5 records out of 104715 total, starting on record 151, ending on 155

Actions