CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5327  CVE-2002-0939  Candidate  The Install Wizard for nCipher MSCAPI CSP 5.50 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protection level than specified by the user (module protection only).  Proposed (20020830)  ACCEPT(6) Alderson, Armstrong, Baker, Cole, Frech, Jones | NOOP(3) Christey, Cox, Foat  Christey> Add "a different issue than CVE-2002-0940" to emphasize | difference.  View
5328  CVE-2002-0940  Candidate  domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protection level than specified by the user (module protection only).  Proposed (20020830)  ACCEPT(3) Baker, Cole, Green | MODIFY(1) Frech | NOOP(4) Christey, Cox, Foat, Wall  Christey> Add "a different issue than CVE-2002-0939" to emphasize | difference. | Frech> XF:mscapi-csp-domesticinstall-key(10356)  View
3838  CVE-2001-1034  Candidate  Format string vulnerability in Hylafax on FreeBSD allows local users to execute arbitrary code via format specifiers in the -h hostname argument for (1) faxrm or (2) faxalter.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(4) Christey, Cole, Foat, Wall  Christey> Acknowledged in: | BUGTRAQ:20020729 HylaFAX - Various Vulnerabilities Fixed | URL:http://archives.neohapsis.com/archives/bugtraq/2002-07/0358.html | Vendor says problem affects all versions "prior to 4.1.3" | Christey> Confirmed by vendor: | BUGTRAQ:20020729 HylaFAX - Various Vulnerabilities Fixed | URL:http://archives.neohapsis.com/archives/bugtraq/2002-07/0358.html | | Also affects OSes other than FreeBSD. | DEBIAN:DSA-148 | URL:http://www.debian.org/security/2002/dsa-148 | Christey> MANDRAKE:MDKSA-2002:055  View
4133  CVE-2001-1329  Candidate  Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root priveleges via a long command line argument.  Proposed (20020502)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | REJECT(1) Christey  Christey> Acknowledged by vendor (Troy Bollinger no less ;-) in: | BUGTRAQ:20010612 Re: (forw) rsh bufferoverflow on AIX 4.2 | URL:http://online.securityfocus.com/archive/1/190630 | | HOWEVER... this looks like a rediscovery of CVE-1999-0101. | Troy"s June 2001 response mentions a gethostbyname() problem | in 1996, which is CVE-1999-0101. | Frech> XF:dns-leng-ovf(637) | XF:ghbn-bo(1751) | Also assigned: CVE-1999-0101 | In description, "privileges" is misspelled.  View
8780  CVE-2004-0352  Candidate  Cisco 11000 Series Content Services Switches (CSS) running WebNS 5.0(x) before 05.0(04.07)S, and 6.10(x) before 06.10(02.05)S allow remote attackers to cause a denial of service (device reset) via a malformed packet to UDP port 5002.  Proposed (20040318)  ACCEPT(4) Armstrong, Baker, Cole, Wall | NOOP(2) Christey, Cox  Christey> According to the Details section of the advisory, the | vulnerability can only be exploited through the management port, which | is "available solely through the physical management interface." So, | change the description to point out that physical access is required. | Thanks to esCERT-UPC for pointing this out.  View

Page 339 of 20943, showing 5 records out of 104715 total, starting on record 1691, ending on 1695

Actions