CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6855  CVE-2003-0026  Candidate  Multiple stack-based buffer overflows in the error handling routines of the minires library, as used in the NSUPDATE capability for ISC DHCPD 3.0 through 3.0.1RC10, allow remote attackers to execute arbitrary code via a DHCP message containing a long hostname.  Modified (20071129)  ACCEPT(4) Baker, Cole, Cox, Wall | MODIFY(1) Frech | NOOP(1) Christey  Frech> XF:dhcpd-minires-multiple-bo(11073) | Christey> MANDRAKE:MDKSA-2003:007 | URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:007 | SUSE:SUSE-SA:2003:0006 | URL:http://www.suse.de/de/security/2003_006_dhcp.html | | Since the SuSE advisory name is "malformed" according to | SuSE"s own convention, make sure that "SuSE-SA:2003:006" is in | the keywords for this CAN.  View
5067  CVE-2002-0677  Candidate  CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.  Modified (20071129)  ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(1) Frech | NOOP(3) Christey, Cox, Foat  Christey> XF:tooltalk-ttdbserverd-ttisclose-validation(9526) | URL:http://www.iss.net/security_center/static/9526.php | BID:5082 | URL:http://www.securityfocus.com/bid/5082 | | HP:HPSBUX0207-199 | URL:http://archives.neohapsis.com/archives/hp/2002-q3/0011.html | Note: while the HP advisory discusses "buffer overflows," | it specifically mentions CA-2002-20, and the text of the | advisory is included in vendor statements for the CERT-VU"s for both | ToolTalk issues covered by CA-2002-20. | | AIXAPAR:IY32368 | URL:http://archives.neohapsis.com/archives/aix/2002-q3/0002.html | AIXAPAR:IY32370 | URL:http://archives.neohapsis.com/archives/aix/2002-q3/0002.html | Christey> HP:HPSBUX0207-199 | URL:http://online.securityfocus.com/advisories/4290 | Christey> SGI:20021101-01-P | Christey> Sun confirmed via email to Matt Wojcik (of MITRE"s OVAL | project) that Sun alert 46022 also addresses this issue. | Frech> XF:tooltalk-ttdbserverd-ttisclose-validation(9526)  View
6867  CVE-2003-0038  Candidate  Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.  Modified (20071129)  ACCEPT(4) Baker, Cole, Cox, Green | NOOP(2) Christey, Wall  Christey> DEBIAN:DSA-436 | URL:http://www.debian.org/security/2004/dsa-436  View
5550  CVE-2002-1166  Candidate  Buffer overflow in John Franks WN Server 1.18.2 through 2.0.0 allows remote attackers to execute arbitrary code via a long GET request.  Modified (20071121)  ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall    View
6854  CVE-2003-0025  Candidate  Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain privileges via certain database functions such as check_prefs() in db.pgsql, as demonstrated using mailbox.php3.  Modified (20071121)  ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Jones | NOOP(2) Christey, Cox  Jones> Change "...gain privileges..." to "...gain additional | privileges..." | Christey> BID:6559 | URL:http://www.securityfocus.com/bid/6559 | XF:imp-multiple-sql-injection(11028) | URL:http://www.iss.net/security_center/static/11028.php | Christey> CONECTIVA:CLA-2003:690 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000690  View

Page 456 of 20943, showing 5 records out of 104715 total, starting on record 2276, ending on 2280

Actions