CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2086  CVE-2000-0509  Candidate  Buffer overflows in the finger and whois demonstration scripts in Sambar Server 4.3 allow remote attackers to execute arbitrary commands via a long hostname.  Proposed (20000712)  ACCEPT(2) Levy, Ozancin | MODIFY(1) Frech | NOOP(2) LeBlanc, Wall  Frech> XF:sambar-dll-bo(4592)  View
2097  CVE-2000-0520  Candidate  Buffer overflow in restore program 0.4b17 and earlier in dump package allows local users to execute arbitrary commands via a long tape name.  Proposed (20000712)  ACCEPT(2) Levy, Prosser | MODIFY(1) Frech | NOOP(4) Christey, LeBlanc, Ozancin, Wall  Christey> ADDREF BUGTRAQ:20000711 MDKSA-2000:018 dump update | URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0166.html | Frech> XF:linux-restore-bo(4647) | Prosser> Add Sources: | http://www.linux-mandrake.com/en/updates/2000/MDKSA-2000-018.php3?dis=6.0 | http://www.redhat.com/support/errata/RHSA-2000-100.html  View
2101  CVE-2000-0524  Candidate  Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From.  Proposed (20000712)  MODIFY(3) Frech, LeBlanc, Levy | NOOP(1) Ozancin | RECAST(1) Wall  Levy> There was plenty of people that could not reproduce the problem although | some did. More research (as in actual testing) is probably required. | LeBlanc> This entry does not specify which versions of Outloook are vulnerable, nor | is that clear from the BUGTRAQ record. It is much too broad to say just | "Outlook" when it is definately not all versions of Outlook. The problem | appears confined to some version of Outlook 97, and if I recall correctly, | there has been a patch for this for quite some time. | Frech> XF:outlook-header-dos(4645) | CHANGE> [Wall changed vote from REVIEWING to RECAST] | Wall> UNABLE TO DUPLICATE  View
2103  CVE-2000-0526  Candidate  mailview.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.  Proposed (20000712)  ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(4) Christey, LeBlanc, Ozancin, Wall  Christey> ADDREF XF:mailstudio-view-files | Frech> XF:mailstudio-view-files(4737)  View
2104  CVE-2000-0527  Candidate  userreg.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.  Proposed (20000712)  ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(4) Christey, LeBlanc, Ozancin, Wall  Christey> Modify description - explicitly mention %0a string; other | metachar"s are filtered | Frech> XF:mailstudio-cgi-input-vaildation(4739)  View

Page 359 of 20943, showing 5 records out of 104715 total, starting on record 1791, ending on 1795

Actions