CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5919  CVE-2002-1535  Candidate  Secure Webserver 1.1 in Raptor 6.5 and Symantec Enterprise Firewall 6.5.2 allows remote attackers to identify IP addresses of hosts on the internal network via a CONNECT request, which generates different error messages if the host is present.  Modified (20071016)  ACCEPT(2) Armstrong, Baker | NOOP(4) Christey, Cole, Cox, Wall  Christey> XF:simple-webserver-topology-disclosure(10363) | URL:http://www.iss.net/security_center/static/10363.php | CONFIRM:http://securityresponse.symantec.com/avcenter/security/Content/2002.10.11a.html  View
5467  CVE-2002-1080  Candidate  The Administration console for Abyss Web Server 1.0.3 before Patch 2 allows remote attackers to gain privileges and modify server configuration via direct requests to CHL files such as (1) srvstatus.chl, (2) consport.chl, (3) general.chl, (4) srvparam.chl, and (5) advanced.chl.  Modified (20071016)  ACCEPT(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall  Frech> CONFIRM:http://www.aprelium.com/news/patch1033.html | Christey> CONFIRM:http://www.aprelium.com/news/patch1033.html  View
5223  CVE-2002-0833  Candidate  Buffer overflow in Eudora 5.1.1 and 5.0-J for Windows, and possibly other versions, allows remote attackers to execute arbitrary code via a multi-part message with a long boundary string.  Modified (20071016)  MODIFY(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall  Christey> BID:5397 | URL:http://www.securityfocus.com/bid/5397 | Frech> XF:eudora-boundary-bo(9765) | Christey> MISC:http://www.lac.co.jp/security/english/snsadv_e/55_e.html  View
5233  CVE-2002-0843  Candidate  Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response.  Modified (20071016)  ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Cox | NOOP(1) Christey  Christey> CONFIRM:http://www.info.apple.com/usen/security/security_updates.html | Cox> Support inclusion decision: a user may well run ApacheBench against | their own server in a DMZ that has been compromised therefore leading | to a break across security zones. | Addref: RHSA-2002:251 | Addref: RHSA-2002:248 | Addref: RHSA-2002:244 | Addref: RHSA-2002:243 | Addref: RHSA-2002:222 | Change Apache Week ref to: http://www.apacheweek.com/issues/02-10-04#security | Christey> SGI:20021105-02-I | URL:ftp://patches.sgi.com/support/free/security/advisories/20021105-02-I | Christey> BUGTRAQ:20021016 Apache 1.3.26 | URL:http://archives.neohapsis.com/archives/bugtraq/2002-10/0229.html | XF:apache-apachebench-response-bo(10281) | URL:http://www.iss.net/security_center/static/10281.php | BID:5996 | URL:http://www.securityfocus.com/bid/5996  View
5046  CVE-2002-0656  Candidate  Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3.  Modified (20071016)  ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Cox | NOOP(2) Christey, Foat  Christey> The CVE content decision "CD:SF-LOC" recommends that multiple | bugs of the same type, in the same version of software, should | be combined. Content decisions such as CD:SF-LOC ensure the | long-term consistency of CVE across all vulnerability reports, | since the amount of detail can vary widely. | Cox> ADDREF:RHSA-2002:163 RHSA-2002:164 RHSA-2002:157 | This issue also affects SSLeay and BSAFE SSL-C | ADDREF: http://www.rsasecurity.com/products/bsafe/bulletins/BSAFE_SSL_Products_Security_Bulletin_Aug_8_2002.pdf | Christey> BUGTRAQ:20021003 Cisco Secure Content Accelerator vulnerable to SSL worm | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=103374616018622&w=2 | CONFIRM:http://www.cisco.com/univercd/cc/td/doc/product/webscale/css/css_sca/sca_320/v320b20.htm#xtocid13 | Christey> I should probably create a separate CAN for the BSAFE issues, | unless there is a codebase relationship. | Christey> XF:openssl-ssl3-sessionid-bo(9716) | URL:http://www.iss.net/security_center/static/9716.php  View

Page 472 of 20943, showing 5 records out of 104715 total, starting on record 2356, ending on 2360

Actions