CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5785 | CVE-2002-1401 | Candidate | Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and earlier allow attackers to cause a denial of service and possibly execute arbitrary code, possibly as a result of an integer overflow. | Modified (20071113) | ACCEPT(3) Armstrong, Cox, Green | NOOP(2) Christey, Cole | CHANGE> [Cox changed vote from NOOP to ACCEPT] | Christey> REDHAT:RHSA-2003:010 | View |
5786 | CVE-2002-1402 | Candidate | Buffer overflows in the (1) TZ and (2) SET TIME ZONE enivronment variables for PostgreSQL 7.2.1 and earlier allow local users to cause a denial of service and possibly execute arbitrary code. | Modified (20071113) | ACCEPT(2) Armstrong, Green | MODIFY(1) Cox | NOOP(1) Cole | Cox> Addref: RHSA-2003:010 | Addref: RHSA-2003:001 | Addref: RHSA-2002:301 | View |
6870 | CVE-2003-0041 | Candidate | Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client. | Modified (20071113) | ACCEPT(4) Armstrong, Cole, Green, Jones | MODIFY(1) Cox | Cox> Addref: RHSA-2003:021 | View |
6871 | CVE-2003-0042 | Candidate | Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character. | Modified (20071113) | ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox | REVIEWING(1) Jones | Jones> [JHJ] RECAST (split?) Only if vulnerability is not null character for both | View |
2776 | CVE-2000-1209 | Candidate | The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida. | Modified (20071113) | ACCEPT(5) Armstrong, Baker, Cole, Green, Wall | MODIFY(1) Frech | NOOP(3) Christey, Cox, Foat | Frech> XF:tumbleweed-mms-blank-password(5072) | XF:msde-mssql-default-password(9154) | May overlap with CVE-2000-0772. | Christey> fix desc - "installed with a default password" appears twice. | View |
Page 464 of 20943, showing 5 records out of 104715 total, starting on record 2316, ending on 2320