CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6857  CVE-2003-0028  Candidate  Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.  Assigned (20030110)  NOOP(1) Christey  Christey> MANDRAKE:MDKSA-2003:043 | (as suggested by Vincent Danen of Mandrake)  View
7637  CVE-2003-0813  Candidate  A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2003-0715, and CVE-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.  Assigned (20030918)  NOOP(1) Christey  Christey> Note: MS04-012 references this CAN and credits eEye, who | describes a similar-looking issue in their advisory COMMENT | "AD20040413A." However, this particular candidate was published by | ISS in 2003. MITRE is investigating this discrepancy and will update | this candidate if necessary.  View
6901  CVE-2003-0072  Candidate  The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes an out-of-bounds read of an array (aka "array overrun").  Assigned (20030204)  NOOP(1) Christey  Christey> MANDRAKE:MDKSA-2003:043 | (as suggested by Vincent Danen of Mandrake)  View
6911  CVE-2003-0082  Candidate  The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").  Assigned (20030210)  NOOP(1) Christey  Christey> MANDRAKE:MDKSA-2003:043 | (as suggested by Vincent Danen of Mandrake)  View
543  CVE-1999-0555  Candidate  A Unix account with a name other than "root" has UID 0, i.e. root privileges.  Proposed (19990728)  NOOP(1) Baker | REJECT(2) Northcutt, Shostack  Northcutt> This is very bogus  View

Page 36 of 20943, showing 5 records out of 104715 total, starting on record 176, ending on 180

Actions