CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5275 | CVE-2002-0885 | Candidate | Multiple buffer overflows in in.rarpd (ARP server) on Solaris, and possibly other operating systems including Caldera UnixWare and Open UNIX, allow remote attackers to execute arbitrary code, possibly via the functions (1) syserr and (2) error. | Proposed (20020830) | ACCEPT(3) Baker, Cole, Frech | MODIFY(1) Alderson | NOOP(5) Armstrong, Christey, Cox, Foat, Jones | Jones> Need clarification/verification. | Alderson> Personally, since this one is not only vague, but extremely vague | and not even confirmed, I believe it should be lumped with the previous one | that has been confirmed and is much less vague. | Christey> Correction: this is a RARP (Reverse Address Resolution | Protocol) server. | A colleague of mine with access to Solaris source has noted | that the affected syslog calls can not be fed user-supplied | data, at least for Solaris; if so, then this is not a vulnerability. | View |
5271 | CVE-2002-0881 | Candidate | Cisco IP Phone (VoIP) models 7910, 7940, and 7960 use a default administrative password, which allows attackers with physical access to the phone to modify the configuration settings. | Proposed (20020830) | ACCEPT(6) Alderson, Armstrong, Baker, Cole, Foat, Frech | MODIFY(1) Jones | NOOP(1) Cox | Jones> Description: "...use a default, publicly-known, and unchangeable | trusted path key combination to access configuration information, which | allows attackers..." | View |
5481 | CVE-2002-1094 | Candidate | Information leaks in Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.5.4 allow remote attackers to obtain potentially sensitive information via the (1) SSH banner, (2) FTP banner, or (3) an incorrect HTTP request. | Proposed (20030317) | ACCEPT(3) Baker, Cole, Green | MODIFY(1) Jones | NOOP(2) Christey, Cox | Jones> Change "...via the (1) SSH banner, (2) FTP banner, or (3) an | incorrect HTTP request." to "...via (1) the SSH banner, (2) the FTP banner, | or (3) an incorrect HTTP request." | Christey> CIAC:M-119 | URL:http://www.ciac.org/ciac/bulletins/m-119.shtml | View |
6854 | CVE-2003-0025 | Candidate | Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain privileges via certain database functions such as check_prefs() in db.pgsql, as demonstrated using mailbox.php3. | Modified (20071121) | ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Jones | NOOP(2) Christey, Cox | Jones> Change "...gain privileges..." to "...gain additional | privileges..." | Christey> BID:6559 | URL:http://www.securityfocus.com/bid/6559 | XF:imp-multiple-sql-injection(11028) | URL:http://www.iss.net/security_center/static/11028.php | Christey> CONECTIVA:CLA-2003:690 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000690 | View |
5276 | CVE-2002-0886 | Candidate | Cisco DSL CPE devices running CBOS 2.4.4 and earlier allows remote attackers to cause a denial of service (hang or memory consumption) via (1) a large packet to the DHCP port, (2) a large packet to the Telnet port, or (3) a flood of large packets to the CPE, which causes the TCP/IP stack to consume large amounts of memory. | Modified (20050601) | ACCEPT(5) Alderson, Armstrong, Baker, Cole, Frech | NOOP(2) Cox, Foat | RECAST(1) Jones | Jones> A single large packet DoS to a listening service (which sounds | like a buffer overflow) seems like a different vulnerability than multiple | large packets (which is admittedly resource consumption). Suggest SPLIT | into two items, prolems 1 and 2 in A, and problem 3 in B. | View |
Page 38 of 20943, showing 5 records out of 104715 total, starting on record 186, ending on 190