CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2649 | CVE-2000-1081 | Candidate | The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. | Modified (20061101) | ACCEPT(3) Baker, Cole, Magdych | MODIFY(1) Frech | NOOP(1) Christey | REVIEWING(1) Wall | Baker> ALready posted in refs | Christey> ADDREF XF:mssql-xp-paraminfo-bo | URL:http://xforce.iss.net/static/5622.php | Frech> XF:mssql-xp-paraminfo-bo(5622) | View |
5794 | CVE-2002-1410 | Candidate | Easy Guestbook CGI programs do not authenticate the administrator, which allows remote attackers to (1) delete entries via direct access of admin.cgi, or (2) reconfigure Guestbook via direct access of config.cgi. | Proposed (20030317) | ACCEPT(1) Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall | Baker> ADD: http://bosen.net/advisories/aresu-adv.002.txt | View |
8763 | CVE-2004-0335 | Candidate | LAN SUITE Web Mail 602Pro, when configured to use the "Directory browsing" feature, allows remote attackers to obtain a directory listing via an HTTP request to (1) index.html, (2) cgi-bin/, or (3) users/. | Proposed (20040318) | ACCEPT(1) Cole | NOOP(2) Cox, Wall | REJECT(1) Armstrong | Armstrong> If this is a design feature - then it should not be classed as a vulnerability. | View |
8571 | CVE-2004-0143 | Candidate | Multiple vulnerabilities in Nokia 6310(i) Mobile phones allow remote attackers to cause a denial of service (reset) via malformed Bluetooth OBject EXchange (OBEX) messages, probably triggering buffer overflows. | Modified (20050518) | ACCEPT(3) Armstrong, Cole, Cox | NOOP(1) Wall | Armstrong> I believe that Mobile phones, PDAs etc are all valid IT devices and should be included as part of the CVE. | View |
4162 | CVE-2001-1358 | Candidate | Vulnerabilities in phpMyChat before 0.14.4 allow local and possibly remote attackers to gain privileges by specifying an alternate library file in the L (localization) parameter. | Proposed (20020611) | ACCEPT(3) Alderson, Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | Alderson> We should be ready to break this out into more seperate | Candidates should more information come to light on this. | Frech> XF:phpmychat-weak-input(9831) | View |
Page 370 of 20943, showing 5 records out of 104715 total, starting on record 1846, ending on 1850