CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5785  CVE-2002-1401  Candidate  Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and earlier allow attackers to cause a denial of service and possibly execute arbitrary code, possibly as a result of an integer overflow.  Modified (20071113)  ACCEPT(3) Armstrong, Cox, Green | NOOP(2) Christey, Cole  CHANGE> [Cox changed vote from NOOP to ACCEPT] | Christey> REDHAT:RHSA-2003:010  View
5786  CVE-2002-1402  Candidate  Buffer overflows in the (1) TZ and (2) SET TIME ZONE enivronment variables for PostgreSQL 7.2.1 and earlier allow local users to cause a denial of service and possibly execute arbitrary code.  Modified (20071113)  ACCEPT(2) Armstrong, Green | MODIFY(1) Cox | NOOP(1) Cole  Cox> Addref: RHSA-2003:010 | Addref: RHSA-2003:001 | Addref: RHSA-2002:301  View
6870  CVE-2003-0041  Candidate  Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.  Modified (20071113)  ACCEPT(4) Armstrong, Cole, Green, Jones | MODIFY(1) Cox  Cox> Addref: RHSA-2003:021  View
6871  CVE-2003-0042  Candidate  Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.  Modified (20071113)  ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox | REVIEWING(1) Jones  Jones> [JHJ] RECAST (split?) Only if vulnerability is not null character for both  View
2776  CVE-2000-1209  Candidate  The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida.  Modified (20071113)  ACCEPT(5) Armstrong, Baker, Cole, Green, Wall | MODIFY(1) Frech | NOOP(3) Christey, Cox, Foat  Frech> XF:tumbleweed-mms-blank-password(5072) | XF:msde-mssql-default-password(9154) | May overlap with CVE-2000-0772. | Christey> fix desc - "installed with a default password" appears twice.  View

Page 464 of 20943, showing 5 records out of 104715 total, starting on record 2316, ending on 2320

Actions