CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2121 | CVE-2000-0544 | Candidate | Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests that contain an invalid data length. | Proposed (20000712) | ACCEPT(2) LeBlanc, Levy | MODIFY(1) Frech | NOOP(1) Ozancin | REVIEWING(2) Christey, Wall | Frech> XF;nt-smb-request-dos(4600) | Christey> Consult with Microsoft to see if this is MS:MS00-066 | Christey> ADDREF MS:MS00-066 | (confirmed offline with David LeBlanc) | Subsequently, add BID:1673 and XF:win2k-rpc-dos(5222) | View |
2122 | CVE-2000-0545 | Candidate | Buffer overflow in mailx mail command (aka Mail) on Linux systems allows local users to gain privileges via a long -c (carbon copy) parameter. | Proposed (20000712) | ACCEPT(2) Levy, Ozancin | MODIFY(1) Frech | NOOP(2) LeBlanc, Wall | REVIEWING(1) Christey | Frech> XF:sgi-mailx-bo(1371) | CVE-2000-0545 seems to be a dupe of CVE-1999-0125 (Buffer overflow in SGI | IRIX mailx program) since they both allow "mail" group privileges. There was | no exploit for SGI"s vuln to compare. | Christey> Since we are taking a split-by-default approach when | there are insufficient details, we should keep this | separate from CVE-1999-0125. The difference in the | time of discovery is also a factor, even if these wind | up being the same problem. However, there just aren"t | enough details to be sure if this is the same problem or not. | Christey> On June 25, 1998, a buffer overflow in mailx via the HOME | environmental variable was posted at: | BUGTRAQ:19980625 security hole in mailx | http://marc.theaimsgroup.com/?l=bugtraq&m=90221103125955&w=2 | | This affected multiple OSes. | | SGI:19980605-01-PX (CVE-1999-0125) was published on September | 29, 1998; while the advisory is short on details, it does | mention a buffer overflow. | | So, there"s enough distinction here (time and what gets | exploited) to say that these should remain split; but | CVE-1999-0125 likely needs to be RECAST to mention other | affected OSes. | View |
2123 | CVE-2000-0546 | Candidate | Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the lastrealm variable in the set_tgtkey function. | Proposed (20000712) | ACCEPT(2) Levy, Ozancin | MODIFY(2) Cox, Frech | NOOP(3) Christey, LeBlanc, Wall | Christey> ADDREF XF:kerberos-lastrealm-bo | Frech> XF:kerberos-lastrealm-bo(4656) | I question whether BID-1338 is appropriate here. | Cox> ADDREF REDHAT:RHSA-2000:031 | View |
2124 | CVE-2000-0547 | Candidate | Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the localrealm variable in the process_v4 function. | Proposed (20000712) | ACCEPT(2) Levy, Ozancin | MODIFY(2) Cox, Frech | NOOP(2) LeBlanc, Wall | Frech> XF:kerberos-localrealm-bo(4657) | I question whether BID-1338 is appropriate here. | Cox> ADDREF REDHAT:RHSA-2000:031 | View |
2125 | CVE-2000-0548 | Entry | Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the e_msg variable in the kerb_err_reply function. | View |
Page 425 of 20943, showing 5 records out of 104715 total, starting on record 2121, ending on 2125