CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5275  CVE-2002-0885  Candidate  Multiple buffer overflows in in.rarpd (ARP server) on Solaris, and possibly other operating systems including Caldera UnixWare and Open UNIX, allow remote attackers to execute arbitrary code, possibly via the functions (1) syserr and (2) error.  Proposed (20020830)  ACCEPT(3) Baker, Cole, Frech | MODIFY(1) Alderson | NOOP(5) Armstrong, Christey, Cox, Foat, Jones  Jones> Need clarification/verification. | Alderson> Personally, since this one is not only vague, but extremely vague | and not even confirmed, I believe it should be lumped with the previous one | that has been confirmed and is much less vague. | Christey> Correction: this is a RARP (Reverse Address Resolution | Protocol) server. | A colleague of mine with access to Solaris source has noted | that the affected syslog calls can not be fed user-supplied | data, at least for Solaris; if so, then this is not a vulnerability.  View
5271  CVE-2002-0881  Candidate  Cisco IP Phone (VoIP) models 7910, 7940, and 7960 use a default administrative password, which allows attackers with physical access to the phone to modify the configuration settings.  Proposed (20020830)  ACCEPT(6) Alderson, Armstrong, Baker, Cole, Foat, Frech | MODIFY(1) Jones | NOOP(1) Cox  Jones> Description: "...use a default, publicly-known, and unchangeable | trusted path key combination to access configuration information, which | allows attackers..."  View
5481  CVE-2002-1094  Candidate  Information leaks in Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.5.4 allow remote attackers to obtain potentially sensitive information via the (1) SSH banner, (2) FTP banner, or (3) an incorrect HTTP request.  Proposed (20030317)  ACCEPT(3) Baker, Cole, Green | MODIFY(1) Jones | NOOP(2) Christey, Cox  Jones> Change "...via the (1) SSH banner, (2) FTP banner, or (3) an | incorrect HTTP request." to "...via (1) the SSH banner, (2) the FTP banner, | or (3) an incorrect HTTP request." | Christey> CIAC:M-119 | URL:http://www.ciac.org/ciac/bulletins/m-119.shtml  View
6854  CVE-2003-0025  Candidate  Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain privileges via certain database functions such as check_prefs() in db.pgsql, as demonstrated using mailbox.php3.  Modified (20071121)  ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Jones | NOOP(2) Christey, Cox  Jones> Change "...gain privileges..." to "...gain additional | privileges..." | Christey> BID:6559 | URL:http://www.securityfocus.com/bid/6559 | XF:imp-multiple-sql-injection(11028) | URL:http://www.iss.net/security_center/static/11028.php | Christey> CONECTIVA:CLA-2003:690 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000690  View
5276  CVE-2002-0886  Candidate  Cisco DSL CPE devices running CBOS 2.4.4 and earlier allows remote attackers to cause a denial of service (hang or memory consumption) via (1) a large packet to the DHCP port, (2) a large packet to the Telnet port, or (3) a flood of large packets to the CPE, which causes the TCP/IP stack to consume large amounts of memory.  Modified (20050601)  ACCEPT(5) Alderson, Armstrong, Baker, Cole, Frech | NOOP(2) Cox, Foat | RECAST(1) Jones  Jones> A single large packet DoS to a listening service (which sounds | like a buffer overflow) seems like a different vulnerability than multiple | large packets (which is admittedly resource consumption). Suggest SPLIT | into two items, prolems 1 and 2 in A, and problem 3 in B.  View

Page 38 of 20943, showing 5 records out of 104715 total, starting on record 186, ending on 190

Actions