CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4033 | CVE-2001-1229 | Candidate | Buffer overflows in (1) Icecast before 1.3.9 and (2) libshout before 1.0.4 allow remote attackers to cause a denial of service (crash) and execute arbitrary code. | Proposed (20020502) | ACCEPT(3) Cole, Cox, Green | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall | Christey> CALDERA:CSSA-2002-020.0 | Frech> XF:icecast-libshout-multiple-bo(9245) | View |
4034 | CVE-2001-1230 | Candidate | Buffer overflows in Icecast before 1.3.10 allow remote attackers to cause a denial of service (crash) and execute arbitrary code. | Proposed (20020502) | ACCEPT(3) Cole, Cox, Green | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall | Christey> CALDERA:CSSA-2002-020.0 | Christey> CONECTIVA:CLSA-2001:387 | Frech> XF:icecast-multiple-bo(9246) | View |
4570 | CVE-2002-0177 | Candidate | Buffer overflows in icecast 1.3.11 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request from an MP3 client. | Modified (20050510) | ACCEPT(3) Cole, Cox, Green | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Foat, Wall | Christey> CALDERA:CSSA-2002-020.0 | Christey> Change "allows" to "allow," and add "as exploited through the | client_login function" (to facilitate matching). | REDHAT:RHSA-2002:063 | Frech> XF:icecast-clientlogin-bo(8741) | View |
4079 | CVE-2001-1275 | Candidate | MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking. | Proposed (20020502) | ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | REVIEWING(1) Christey | Christey> CALDERA:CSSA-2001-006.0 specifically says they"re not | vulnerable to this issue. So, do we remove the reference | (because they aren"t affected by this problem), or do we | keep the reference because it specifically mentions this | issue? | | Need to review the other advisories; they don"t necessarily | have the details to know whether they"re addressing this | problem or not (the overflow mentioned in these refs is | covered by CVE-2001-1274). MANDRAKE:MDKSA-2001:014 | clearly identifies this issue. | | FREEBSD:FreeBSD-SA-01:16 discussed "remote vulerabilities" | (plural), which *could* include this issue, but it is not | absolutely certain. REDHAT:RHSA-2001:003 refers to | "information protection issues," but that"s not clear enough | either. | | Thanks to John Segura of secureinfo.com for noticing this | issue. | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:mysql-show-grants-password(9996) | View |
5224 | CVE-2002-0834 | Candidate | Buffer overflow in the ISIS dissector for Ethereal 0.9.5 and earlier allows remote attackers to cause a denial of service or execute arbitrary code via malformed packets. | Proposed (20020830) | ACCEPT(5) Armstrong, Baker, Cole, Cox, Foat | MODIFY(1) Frech | NOOP(2) Christey, Wall | Christey> BUGTRAQ:20020830 GLSA: ethereal | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=103072249023973&w=2 | Christey> DEBIAN:DSA-162 | URL:http://www.debian.org/security/2002/dsa-162 | Christey> XF:ethereal-isis-dissector-bo(9942) | URL:http://www.iss.net/security_center/static/9942.php | Frech> XF:ethereal-isis-dissector-bo(9942) | Christey> REDHAT:RHSA-2002:036 | URL:http://www.redhat.com/support/errata/RHSA-2002-036.html | View |
Page 325 of 20943, showing 5 records out of 104715 total, starting on record 1621, ending on 1625