CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5223 | CVE-2002-0833 | Candidate | Buffer overflow in Eudora 5.1.1 and 5.0-J for Windows, and possibly other versions, allows remote attackers to execute arbitrary code via a multi-part message with a long boundary string. | Modified (20071016) | MODIFY(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall | Christey> BID:5397 | URL:http://www.securityfocus.com/bid/5397 | Frech> XF:eudora-boundary-bo(9765) | Christey> MISC:http://www.lac.co.jp/security/english/snsadv_e/55_e.html | View |
5107 | CVE-2002-0717 | Candidate | PHP 4.2.0 and 4.2.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP POST request with certain arguments in a multipart/form-data form, which generates an error condition that is not properly handled and causes improper memory to be freed. | Proposed (20020726) | ACCEPT(5) Armstrong, Baker, Cole, Cox, Frech | NOOP(2) Christey, Foat | REVIEWING(1) Wall | Christey> BID:5278 | URL:http://www.securityfocus.com/bid/5278 | HP:HPSBUX0208-207 | URL:http://online.securityfocus.com/advisories/4362 | View |
5027 | CVE-2002-0637 | Candidate | InterScan VirusWall 3.52 build 1462 allows remote attackers to bypass virus protection via e-mail messages with headers that violate RFC specifications by having (or missing) space characters in unexpected places (aka "space gap"), such as (1) Content-Type :", (2) "Content-Transfer-Encoding :", (3) no space before a boundary declaration, or (4) "boundary= ", which is processed by Outlook Express. | Modified (20071101) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall | Christey> BID:5259 | URL:http://online.securityfocus.com/bid/5259 | CONFIRM:http://solutionbank.antivirus.com/solutions/solutionDetail.asp?solutionId=11948 | | According to Axel Pettinger, Solaris 3.7 build 1070 | is affected by the "boundary space (trailing)" and "Boundary | Space (prefix)" problems, but not the content-type or transfer | encoding issues. That version clearly has some overlap with | this issue, but since a different build and version number are | affected, perhaps a separate candidate needs to be created. | More information on that issue is at: | http://solutionbank.antivirus.com/solutions/solutiondetail.asp?solutionID=12142 | | Baker> http://solutionbank.antivirus.com/solutions/solutionDetail.asp?solutionID=11948 | Frech> XF:interscan-viruswall-protection-bypass(9464) | View |
4548 | CVE-2002-0154 | Candidate | Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of service or execute arbitrary code via a database query with certain long arguments. | Modified (20061101) | ACCEPT(5) Armstrong, Cole, Foat, Green, Wall | MODIFY(1) Frech | NOOP(2) Christey, Cox | Christey> BID:4231 | URL:http://www.securityfocus.com/bid/4231 | XF:mssql-xp-dirtree-bo(8359) | URL:http://www.iss.net/security_center/static/8359.php | | Need to specifically mention xp_dirtree. | Christey> CERT:CA-2002-22 | CERT-VN:VU#627275 | Frech> XF:mssql-multiple-xp-bo(8359) | View |
3985 | CVE-2001-1181 | Candidate | Dynamically Loadable Kernel Module (dlkm) static kernel symbol table in HP-UX 11.11 is not properly configured, which allows local users to gain privileges. | Modified (20090302) | ACCEPT(6) Armstrong, Baker, Cole, Frech, Green, Ziese | NOOP(3) Christey, Foat, Wall | Christey> BID:3069 | URL:http://www.securityfocus.com/bid/3069 | View |
Page 329 of 20943, showing 5 records out of 104715 total, starting on record 1641, ending on 1645