CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1877 | CVE-2000-0299 | Candidate | Buffer overflow in WebObjects.exe in the WebObjects Developer 4.5 package allows remote attackers to cause a denial of service via an HTTP request with long headers such as Accept. | Proposed (20000426) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Williams | REVIEWING(1) Levy | Christey> ADDREF XF:webobjects-post-dos | Frech> XF:webobjects-post-dos | Christey> See http://til.info.apple.com/techinfo.nsf/artnum/n75087 | Document says: | "A request with a large, malformed http header can crash a WOApp" | (Apple reference #2470254) appears to be the acknowledgement needed. | | Is this sufficient acknowledgement? This is dated AUgust 24, | but the initial disclosure occurred on April 4. | Christey> BID:1896 | View |
2650 | CVE-2000-1082 | Candidate | The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. | Proposed (20001219) | ACCEPT(3) Baker, Cole, Magdych | MODIFY(1) Frech | NOOP(1) Christey | REVIEWING(1) Wall | Christey> ADDREF XF:mssql-xp-paraminfo-bo | URL:http://xforce.iss.net/static/5622.php | Frech> XF:mssql-xp-paraminfo-bo(5622) | View |
2651 | CVE-2000-1083 | Candidate | The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. | Proposed (20001219) | ACCEPT(3) Baker, Cole, Magdych | MODIFY(1) Frech | NOOP(1) Christey | REVIEWING(1) Wall | Christey> ADDREF XF:mssql-xp-paraminfo-bo | URL:http://xforce.iss.net/static/5622.php | Frech> XF:mssql-xp-paraminfo-bo(5622) | View |
2652 | CVE-2000-1084 | Candidate | The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. | Proposed (20001219) | ACCEPT(3) Baker, Cole, Magdych | MODIFY(1) Frech | NOOP(1) Christey | REVIEWING(1) Wall | Christey> ADDREF XF:mssql-xp-paraminfo-bo | URL:http://xforce.iss.net/static/5622.php | Frech> XF:mssql-xp-paraminfo-bo(5622) | View |
2103 | CVE-2000-0526 | Candidate | mailview.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. | Proposed (20000712) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(4) Christey, LeBlanc, Ozancin, Wall | Christey> ADDREF XF:mailstudio-view-files | Frech> XF:mailstudio-view-files(4737) | View |
Page 332 of 20943, showing 5 records out of 104715 total, starting on record 1656, ending on 1660