CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5327 | CVE-2002-0939 | Candidate | The Install Wizard for nCipher MSCAPI CSP 5.50 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protection level than specified by the user (module protection only). | Proposed (20020830) | ACCEPT(6) Alderson, Armstrong, Baker, Cole, Frech, Jones | NOOP(3) Christey, Cox, Foat | Christey> Add "a different issue than CVE-2002-0940" to emphasize | difference. | View |
5328 | CVE-2002-0940 | Candidate | domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protection level than specified by the user (module protection only). | Proposed (20020830) | ACCEPT(3) Baker, Cole, Green | MODIFY(1) Frech | NOOP(4) Christey, Cox, Foat, Wall | Christey> Add "a different issue than CVE-2002-0939" to emphasize | difference. | Frech> XF:mscapi-csp-domesticinstall-key(10356) | View |
3838 | CVE-2001-1034 | Candidate | Format string vulnerability in Hylafax on FreeBSD allows local users to execute arbitrary code via format specifiers in the -h hostname argument for (1) faxrm or (2) faxalter. | Proposed (20020131) | ACCEPT(2) Frech, Green | NOOP(4) Christey, Cole, Foat, Wall | Christey> Acknowledged in: | BUGTRAQ:20020729 HylaFAX - Various Vulnerabilities Fixed | URL:http://archives.neohapsis.com/archives/bugtraq/2002-07/0358.html | Vendor says problem affects all versions "prior to 4.1.3" | Christey> Confirmed by vendor: | BUGTRAQ:20020729 HylaFAX - Various Vulnerabilities Fixed | URL:http://archives.neohapsis.com/archives/bugtraq/2002-07/0358.html | | Also affects OSes other than FreeBSD. | DEBIAN:DSA-148 | URL:http://www.debian.org/security/2002/dsa-148 | Christey> MANDRAKE:MDKSA-2002:055 | View |
4133 | CVE-2001-1329 | Candidate | Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root priveleges via a long command line argument. | Proposed (20020502) | ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | REJECT(1) Christey | Christey> Acknowledged by vendor (Troy Bollinger no less ;-) in: | BUGTRAQ:20010612 Re: (forw) rsh bufferoverflow on AIX 4.2 | URL:http://online.securityfocus.com/archive/1/190630 | | HOWEVER... this looks like a rediscovery of CVE-1999-0101. | Troy"s June 2001 response mentions a gethostbyname() problem | in 1996, which is CVE-1999-0101. | Frech> XF:dns-leng-ovf(637) | XF:ghbn-bo(1751) | Also assigned: CVE-1999-0101 | In description, "privileges" is misspelled. | View |
8780 | CVE-2004-0352 | Candidate | Cisco 11000 Series Content Services Switches (CSS) running WebNS 5.0(x) before 05.0(04.07)S, and 6.10(x) before 06.10(02.05)S allow remote attackers to cause a denial of service (device reset) via a malformed packet to UDP port 5002. | Proposed (20040318) | ACCEPT(4) Armstrong, Baker, Cole, Wall | NOOP(2) Christey, Cox | Christey> According to the Details section of the advisory, the | vulnerability can only be exploited through the management port, which | is "available solely through the physical management interface." So, | change the description to point out that physical access is required. | Thanks to esCERT-UPC for pointing this out. | View |
Page 339 of 20943, showing 5 records out of 104715 total, starting on record 1691, ending on 1695