CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2649  CVE-2000-1081  Candidate  The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.  Modified (20061101)  ACCEPT(3) Baker, Cole, Magdych | MODIFY(1) Frech | NOOP(1) Christey | REVIEWING(1) Wall  Baker> ALready posted in refs | Christey> ADDREF XF:mssql-xp-paraminfo-bo | URL:http://xforce.iss.net/static/5622.php | Frech> XF:mssql-xp-paraminfo-bo(5622)  View
5794  CVE-2002-1410  Candidate  Easy Guestbook CGI programs do not authenticate the administrator, which allows remote attackers to (1) delete entries via direct access of admin.cgi, or (2) reconfigure Guestbook via direct access of config.cgi.  Proposed (20030317)  ACCEPT(1) Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall  Baker> ADD: http://bosen.net/advisories/aresu-adv.002.txt  View
8763  CVE-2004-0335  Candidate  LAN SUITE Web Mail 602Pro, when configured to use the "Directory browsing" feature, allows remote attackers to obtain a directory listing via an HTTP request to (1) index.html, (2) cgi-bin/, or (3) users/.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(2) Cox, Wall | REJECT(1) Armstrong  Armstrong> If this is a design feature - then it should not be classed as a vulnerability.  View
8571  CVE-2004-0143  Candidate  Multiple vulnerabilities in Nokia 6310(i) Mobile phones allow remote attackers to cause a denial of service (reset) via malformed Bluetooth OBject EXchange (OBEX) messages, probably triggering buffer overflows.  Modified (20050518)  ACCEPT(3) Armstrong, Cole, Cox | NOOP(1) Wall  Armstrong> I believe that Mobile phones, PDAs etc are all valid IT devices and should be included as part of the CVE.  View
4162  CVE-2001-1358  Candidate  Vulnerabilities in phpMyChat before 0.14.4 allow local and possibly remote attackers to gain privileges by specifying an alternate library file in the L (localization) parameter.  Proposed (20020611)  ACCEPT(3) Alderson, Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Alderson> We should be ready to break this out into more seperate | Candidates should more information come to light on this. | Frech> XF:phpmychat-weak-input(9831)  View

Page 370 of 20943, showing 5 records out of 104715 total, starting on record 1846, ending on 1850

Actions