CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6857 | CVE-2003-0028 | Candidate | Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391. | Assigned (20030110) | NOOP(1) Christey | Christey> MANDRAKE:MDKSA-2003:043 | (as suggested by Vincent Danen of Mandrake) | View |
7637 | CVE-2003-0813 | Candidate | A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2003-0715, and CVE-2003-0528, and as demonstrated by certain exploits against those vulnerabilities. | Assigned (20030918) | NOOP(1) Christey | Christey> Note: MS04-012 references this CAN and credits eEye, who | describes a similar-looking issue in their advisory COMMENT | "AD20040413A." However, this particular candidate was published by | ISS in 2003. MITRE is investigating this discrepancy and will update | this candidate if necessary. | View |
6901 | CVE-2003-0072 | Candidate | The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes an out-of-bounds read of an array (aka "array overrun"). | Assigned (20030204) | NOOP(1) Christey | Christey> MANDRAKE:MDKSA-2003:043 | (as suggested by Vincent Danen of Mandrake) | View |
6911 | CVE-2003-0082 | Candidate | The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun"). | Assigned (20030210) | NOOP(1) Christey | Christey> MANDRAKE:MDKSA-2003:043 | (as suggested by Vincent Danen of Mandrake) | View |
543 | CVE-1999-0555 | Candidate | A Unix account with a name other than "root" has UID 0, i.e. root privileges. | Proposed (19990728) | NOOP(1) Baker | REJECT(2) Northcutt, Shostack | Northcutt> This is very bogus | View |
Page 36 of 20943, showing 5 records out of 104715 total, starting on record 176, ending on 180