CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2193 | CVE-2000-0617 | Candidate | Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long USER environmental variable. | Proposed (20000719) | ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(4) Christey, LeBlanc, Magdych, Wall | Frech> XF:xconq-elevate-privileges(4995) | Christey> ADDREF BID:1495 | ADDREF URL:http://www.securityfocus.com/bid/1495 | CHANGE> [Levy changed vote from REVIEWING to ACCEPT] | CHANGE> [Magdych changed vote from REVIEWING to NOOP] | View |
2194 | CVE-2000-0618 | Candidate | Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long DISPLAY environmental variable. | Proposed (20000719) | ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(4) Christey, LeBlanc, Magdych, Wall | Frech> XF:xconq-elevate-privileges(4995) | Christey> ADDREF BID:1495 | ADDREF URL:http://www.securityfocus.com/bid/1495 | CHANGE> [Levy changed vote from REVIEWING to ACCEPT] | CHANGE> [Magdych changed vote from REVIEWING to NOOP] | View |
2051 | CVE-2000-0473 | Candidate | Buffer overflow in AnalogX SimpleServer 1.05 allows a remote attacker to cause a denial of service via a long GET request for a program in the cgi-bin directory. | Proposed (20000712) | ACCEPT(1) Levy | MODIFY(1) Frech | REVIEWING(1) Christey | Christey> Appears to be the same as, or similar to, CVE-2000-0011, which was | also discovered by USSR. Comments on the AnalogX web site are | decidedly sparse. In CVE-2000-0011, USSR only claims that | the vendor was informed, so is this still the same problem? | | XF:simpleserver-long-url-dos | Frech> XF:simpleserver-long-url-dos(4693) | Please review whether your BUGTRAQ:19991231 reference is correct; seems like | this is the reference to CVE-2000-0011: Buffer overflow in AnalogX | SimpleServer:WWW HTTP server allows remote attackers to execute commands via | a long GET request. They are subtle; almost the only thing that changed was | the version. | A possible reference is "Remote DoS attack in AnalogX SimpleServer WWW | Version 1.05 Vulnerability" at http://www.ussrback.com/labs45.html. | View |
2054 | CVE-2000-0476 | Candidate | xterm, Eterm, and rxvt allow an attacker to cause a denial of service by embedding certain escape characters which force the window to be resized. | Proposed (20000712) | ACCEPT(2) Levy, Ozancin | MODIFY(1) Frech | NOOP(2) LeBlanc, Wall | Frech> XF:xterm-control-characters-dos(4987) | View |
2057 | CVE-2000-0479 | Candidate | Dragon FTP server allows remote attackers to cause a denial of service via a long USER command. | Proposed (20000712) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(1) Christey | Christey> XF:dragon-ftp-dos | Frech> XF:dragon-ftp-dos(4691) | View |
Page 357 of 20943, showing 5 records out of 104715 total, starting on record 1781, ending on 1785