CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2647 | CVE-2000-1079 | Candidate | Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram. | Modified (20061101) | ACCEPT(3) Baker, Mell, Wall | NOOP(1) Cole | REVIEWING(1) Christey | Wall> No known exploit or patch yet. | Christey> This was a little controversial, if I recall correctly. | View |
2649 | CVE-2000-1081 | Candidate | The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. | Modified (20061101) | ACCEPT(3) Baker, Cole, Magdych | MODIFY(1) Frech | NOOP(1) Christey | REVIEWING(1) Wall | Baker> ALready posted in refs | Christey> ADDREF XF:mssql-xp-paraminfo-bo | URL:http://xforce.iss.net/static/5622.php | Frech> XF:mssql-xp-paraminfo-bo(5622) | View |
4447 | CVE-2002-0053 | Candidate | Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers to cause a denial of service or execute arbitrary code via a malformed management request. NOTE: this candidate may be split or merged with other candidates. This and other PROTOS-related candidates, especially CVE-2002-0012 and CVE-2002-0013, will be updated when more accurate information is available. | Modified (20061101) | ACCEPT(5) Cole, Foat, Green, Wall, Ziese | View | |
4450 | CVE-2002-0056 | Candidate | Buffer overflow in SQL Server 7.0 and 2000 allows remote attackers to execute arbitrary code via a long OLE DB provider name to (1) OpenDataSource or (2) OpenRowset in an ad hoc connection. | Modified (20061101) | ACCEPT(5) Cole, Foat, Green, Wall, Ziese | MODIFY(1) Christey | Christey> Consider adding BID:4135 | CHANGE> [Christey changed vote from NOOP to MODIFY] | Christey> ADDREF BID:4135 | XF:mssql-oledb-adhoc-bo(8243) | URL:http://www.iss.net/security_center/static/8243.php | Christey> CIAC:M-044 | URL:http://www.ciac.org/ciac/bulletins/m-044.shtml | CERT-VN:VU#619707 | URL:http://www.kb.cert.org/vuls/id/619707 | View |
4478 | CVE-2002-0084 | Candidate | Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument. | Modified (20061101) | ACCEPT(3) Cole, Green, Wall | NOOP(3) Christey, Foat, Ziese | Christey> CERT:CA-2002-11 | CERT-VN:VU#635811 | AUSCERT:AA-2002.01 | URL:http://www.auscert.org.au/Information/Advisories/advisory/AA-2002.01.txt | Christey> BUGTRAQ:20020429 eSecurityOnline Security Advisory 4198 - Sun Solaris cachefsd mount file buffer overflow vulnerability | URL:http://online.securityfocus.com/archive/1/270135 | Christey> ADDREF CERT-VN:VU#161931 | ADDREF BUGTRAQ:20020429 eSecurityOnline Security Advisory 4198 - Sun Solaris cachefsd mount file buffer overflow vulnerability | ADDREF CONFIRM:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F44309 | | Note: this is a different vulnerability than CVE-2002-0033. | However, if there are different patches for the 2 issues, then | they may need to be merged per CD:SF-LOC. | | Add that the affected function is fscache_setup() | Christey> VULNWATCH:20020429 [VulnWatch] eSecurityOnline Security Advisory 4198 - Sun Solaris cachefsd mou nt file buffer overflow vulnerability | URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0048.html | BID:4631 | URL:http://www.securityfocus.com/bid/4631 | View |
Page 481 of 20943, showing 5 records out of 104715 total, starting on record 2401, ending on 2405