CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2647  CVE-2000-1079  Candidate  Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram.  Modified (20061101)  ACCEPT(3) Baker, Mell, Wall | NOOP(1) Cole | REVIEWING(1) Christey  Wall> No known exploit or patch yet. | Christey> This was a little controversial, if I recall correctly.  View
2649  CVE-2000-1081  Candidate  The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.  Modified (20061101)  ACCEPT(3) Baker, Cole, Magdych | MODIFY(1) Frech | NOOP(1) Christey | REVIEWING(1) Wall  Baker> ALready posted in refs | Christey> ADDREF XF:mssql-xp-paraminfo-bo | URL:http://xforce.iss.net/static/5622.php | Frech> XF:mssql-xp-paraminfo-bo(5622)  View
4447  CVE-2002-0053  Candidate  Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers to cause a denial of service or execute arbitrary code via a malformed management request. NOTE: this candidate may be split or merged with other candidates. This and other PROTOS-related candidates, especially CVE-2002-0012 and CVE-2002-0013, will be updated when more accurate information is available.  Modified (20061101)  ACCEPT(5) Cole, Foat, Green, Wall, Ziese    View
4450  CVE-2002-0056  Candidate  Buffer overflow in SQL Server 7.0 and 2000 allows remote attackers to execute arbitrary code via a long OLE DB provider name to (1) OpenDataSource or (2) OpenRowset in an ad hoc connection.  Modified (20061101)  ACCEPT(5) Cole, Foat, Green, Wall, Ziese | MODIFY(1) Christey  Christey> Consider adding BID:4135 | CHANGE> [Christey changed vote from NOOP to MODIFY] | Christey> ADDREF BID:4135 | XF:mssql-oledb-adhoc-bo(8243) | URL:http://www.iss.net/security_center/static/8243.php | Christey> CIAC:M-044 | URL:http://www.ciac.org/ciac/bulletins/m-044.shtml | CERT-VN:VU#619707 | URL:http://www.kb.cert.org/vuls/id/619707  View
4478  CVE-2002-0084  Candidate  Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument.  Modified (20061101)  ACCEPT(3) Cole, Green, Wall | NOOP(3) Christey, Foat, Ziese  Christey> CERT:CA-2002-11 | CERT-VN:VU#635811 | AUSCERT:AA-2002.01 | URL:http://www.auscert.org.au/Information/Advisories/advisory/AA-2002.01.txt | Christey> BUGTRAQ:20020429 eSecurityOnline Security Advisory 4198 - Sun Solaris cachefsd mount file buffer overflow vulnerability | URL:http://online.securityfocus.com/archive/1/270135 | Christey> ADDREF CERT-VN:VU#161931 | ADDREF BUGTRAQ:20020429 eSecurityOnline Security Advisory 4198 - Sun Solaris cachefsd mount file buffer overflow vulnerability | ADDREF CONFIRM:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F44309 | | Note: this is a different vulnerability than CVE-2002-0033. | However, if there are different patches for the 2 issues, then | they may need to be merged per CD:SF-LOC. | | Add that the affected function is fscache_setup() | Christey> VULNWATCH:20020429 [VulnWatch] eSecurityOnline Security Advisory 4198 - Sun Solaris cachefsd mou nt file buffer overflow vulnerability | URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0048.html | BID:4631 | URL:http://www.securityfocus.com/bid/4631  View

Page 481 of 20943, showing 5 records out of 104715 total, starting on record 2401, ending on 2405

Actions