CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4433 | CVE-2002-0039 | Candidate | rpcbind in SGI IRIX 6.5 through 6.5.15f, and possibly earlier versions, allows remote attackers to cause a denial of service (crash) via malformed RPC packets with invalid lengths. | Proposed (20020502) | ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cox, Foat, Wall | RECAST(3) Baker, Christey, Levy | Christey> CVE-2002-0039 (SGI rpcbind) is the same problem as | CVE-2001-1124 (HP rpcbind). These 2 candidates need to be | merged. | Christey> Consider adding BID:4386 | Christey> XF:irix-invalid-rpc-dos(8668) | URL:http://www.iss.net/security_center/static/8668.php | BID:4386 | URL:http://www.securityfocus.com/bid/4386 | Levy> BID 4386 will be merged into BID 3400. | Frech> XF:irix-invalid-rpc-dos(8668) | View |
2653 | CVE-2000-1085 | Candidate | The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. | Proposed (20001219) | ACCEPT(4) Baker, Cole, Magdych, Wall | MODIFY(1) Frech | REVIEWING(1) Christey | Christey> CVE-2000-1085, CVE-2000-1086, CVE-2000-1087, and CVE-2000-1088 | all have abstraction issues; perhaps they should be RECAST | into a single candidate. | Christey> ADDREF XF:mssql-xp-paraminfo-bo | URL:http://xforce.iss.net/static/5622.php | Frech> XF:mssql-xp-paraminfo-bo(5622) | View |
2654 | CVE-2000-1086 | Candidate | The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. | Proposed (20001219) | ACCEPT(4) Baker, Cole, Magdych, Wall | MODIFY(1) Frech | REVIEWING(1) Christey | Christey> CVE-2000-1085, CVE-2000-1086, CVE-2000-1087, and CVE-2000-1088 | all have abstraction issues; perhaps they should be RECAST | into a single candidate. | Christey> ADDREF XF:mssql-xp-paraminfo-bo | URL:http://xforce.iss.net/static/5622.php | Frech> XF:mssql-xp-paraminfo-bo(5622) | View |
2655 | CVE-2000-1087 | Candidate | The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. | Proposed (20001219) | ACCEPT(4) Baker, Cole, Magdych, Wall | MODIFY(1) Frech | REVIEWING(1) Christey | Christey> CVE-2000-1085, CVE-2000-1086, CVE-2000-1087, and CVE-2000-1088 | all have abstraction issues; perhaps they should be RECAST | into a single candidate. | Christey> ADDREF XF:mssql-xp-paraminfo-bo | URL:http://xforce.iss.net/static/5622.php | Frech> XF:mssql-xp-paraminfo-bo(5622) | View |
2656 | CVE-2000-1088 | Candidate | The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. | Proposed (20001219) | ACCEPT(4) Baker, Cole, Magdych, Wall | MODIFY(1) Frech | REVIEWING(1) Christey | Christey> CVE-2000-1085, CVE-2000-1086, CVE-2000-1087, and CVE-2000-1088 | all have abstraction issues; perhaps they should be RECAST | into a single candidate. | Christey> ADDREF XF:mssql-xp-paraminfo-bo | URL:http://xforce.iss.net/static/5622.php | Frech> XF:mssql-xp-paraminfo-bo(5622) | View |
Page 314 of 20943, showing 5 records out of 104715 total, starting on record 1566, ending on 1570