CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2654 | CVE-2000-1086 | Candidate | The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. | Proposed (20001219) | ACCEPT(4) Baker, Cole, Magdych, Wall | MODIFY(1) Frech | REVIEWING(1) Christey | Christey> CVE-2000-1085, CVE-2000-1086, CVE-2000-1087, and CVE-2000-1088 | all have abstraction issues; perhaps they should be RECAST | into a single candidate. | Christey> ADDREF XF:mssql-xp-paraminfo-bo | URL:http://xforce.iss.net/static/5622.php | Frech> XF:mssql-xp-paraminfo-bo(5622) | View |
2655 | CVE-2000-1087 | Candidate | The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. | Proposed (20001219) | ACCEPT(4) Baker, Cole, Magdych, Wall | MODIFY(1) Frech | REVIEWING(1) Christey | Christey> CVE-2000-1085, CVE-2000-1086, CVE-2000-1087, and CVE-2000-1088 | all have abstraction issues; perhaps they should be RECAST | into a single candidate. | Christey> ADDREF XF:mssql-xp-paraminfo-bo | URL:http://xforce.iss.net/static/5622.php | Frech> XF:mssql-xp-paraminfo-bo(5622) | View |
2656 | CVE-2000-1088 | Candidate | The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. | Proposed (20001219) | ACCEPT(4) Baker, Cole, Magdych, Wall | MODIFY(1) Frech | REVIEWING(1) Christey | Christey> CVE-2000-1085, CVE-2000-1086, CVE-2000-1087, and CVE-2000-1088 | all have abstraction issues; perhaps they should be RECAST | into a single candidate. | Christey> ADDREF XF:mssql-xp-paraminfo-bo | URL:http://xforce.iss.net/static/5622.php | Frech> XF:mssql-xp-paraminfo-bo(5622) | View |
2667 | CVE-2000-1100 | Candidate | The default configuration for PostACI webmail system installs the /includes/global.inc configuration file within the web root, which allows remote attackers to read sensitive information such as database usernames and passwords via a direct HTTP GET request. | Proposed (20001219) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Cole, Wall | Frech> XF:postaci-webmail-reveal-passwords(5612) | View |
2669 | CVE-2000-1102 | Candidate | PTlink IRCD 3.5.3 and PTlink Services 1.8.1 allow remote attackers to cause a denial of service (server crash) via "mode +owgscfxeb" and "oper" commands. | Proposed (20001219) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF:ptlink-ircd-mode-dos(5589) | View |
Page 324 of 20943, showing 5 records out of 104715 total, starting on record 1616, ending on 1620