CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5593 | CVE-2002-1209 | Candidate | Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files via ".." (dot-dot backslash) sequences in a GET request. | Modified (20071101) | ACCEPT(2) Baker, Green | NOOP(3) Cole, Cox, Wall | Green> EXPLOIT | View |
5596 | CVE-2002-1212 | Candidate | Buffer overflow in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to cause a denial of service (crash) via a long HTTP GET request. | Modified (20071101) | ACCEPT(2) Armstrong, Cole | NOOP(3) Balinsky, Cox, Wall | Balinsky> Links to software are dead. Cannot verify. | View |
5363 | CVE-2002-0975 | Candidate | Buffer overflow in Microsoft DirectX Files Viewer ActiveX control (xweb.ocx) 2.0.6.15 and earlier allows remote attackers to execute arbitrary via a long File parameter. | Modified (20071101) | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Cox, Foat | REVIEWING(1) Wall | Christey> ADDREF MS:MS02-066 - "the patch sets the Kill Bit on a legacy | DirectX ActiveX control which has been retired but which has a | security vulnerability." | ADDREF MSKB:Q810202 - deals with "a security vulnerability | that exists in the DirectX Files Viewer control (Xweb.ocx)" | | Thanks to Andrew G. Tereschenko (the researcher) for this | additional information. | Frech> XF:ms-directx-files-viewer-bo(9877) | Christey> fix typo: "execute arbitrary [CODE]" | View |
5111 | CVE-2002-0721 | Candidate | Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt. | Modified (20071101) | ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(2) Foat, Frech | NOOP(2) Christey, Cox | Foat> The description should list MSDE 1.0 and MSDE 2000 as acknowledged by | Microsoft. | Christey> CERT-VN:VU#818939 | URL:http://www.kb.cert.org/vuls/id/818939 | CERT-VN:VU#939675 | URL:http://www.kb.cert.org/vuls/id/939675 | CERT-VN:VU#399531 | URL:http://www.kb.cert.org/vuls/id/399531 | BID:5481 | URL:http://www.securityfocus.com/bid/5481 | XF:mssql-xp-weak-permissions(9857) | URL:http://www.iss.net/security_center/static/9857.php | Frech> XF:mssql-xp-weak-permissions(9857) | View |
8665 | CVE-2004-0237 | Candidate | Directory traversal vulnerability in index.php in Aprox PHP Portal allows remote attackers to read arbitrary files via a full pathname in the show parameter. | Modified (20071031) | NOOP(5) Armstrong, Cole, Cox, Green, Wall | View |
Page 468 of 20943, showing 5 records out of 104715 total, starting on record 2336, ending on 2340