CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2426  CVE-2000-0857  Candidate  The logging capability in muh 2.05d IRC server does not properly cleanse user-injected format strings, which allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed nickname.  Proposed (20001018)  ACCEPT(4) Baker, Cole, Collins, Frech | NOOP(4) Armstrong, Christey, Magdych, Wall  Cole> HAS-INDEPENDENT-CONFIRMATION | Christey> ADDREF FREEBSD:FreeBSD-SA-00:57 | CHANGE> [Magdych changed vote from REVIEWING to NOOP]  View
2435  CVE-2000-0866  Candidate  Interbase 6 SuperServer for Linux allows an attacker to cause a denial of service via a query containing 0 bytes.  Proposed (20001018)  ACCEPT(2) Baker, Collins | NOOP(3) Armstrong, Cole, Wall    View
2441  CVE-2000-0872  Candidate  explorer.php in PhotoAlbum 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack.  Proposed (20001018)  ACCEPT(2) Baker, Collins | NOOP(3) Armstrong, Cole, Wall    View
2448  CVE-2000-0879  Candidate  LPPlus programs dccsched, dcclpdser, dccbkst, dccshut, dcclpdshut, and dccbkstshut are installed setuid root and world executable, which allows arbitrary local users to start and stop various LPD services.  Proposed (20001018)  ACCEPT(2) Baker, Collins | NOOP(3) Armstrong, Cole, Wall    View
2449  CVE-2000-0880  Candidate  LPPlus creates the lpdprocess file with world-writeable permissions, which allows local users to kill arbitrary processes by specifying an alternate process ID and using the setuid dcclpdshut program to kill the process that was specified in the lpdprocess file.  Proposed (20001018)  ACCEPT(2) Baker, Collins | NOOP(3) Armstrong, Cole, Wall    View

Page 343 of 20943, showing 5 records out of 104715 total, starting on record 1711, ending on 1715

Actions