CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4548  CVE-2002-0154  Candidate  Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of service or execute arbitrary code via a database query with certain long arguments.  Modified (20061101)  ACCEPT(5) Armstrong, Cole, Foat, Green, Wall | MODIFY(1) Frech | NOOP(2) Christey, Cox  Christey> BID:4231 | URL:http://www.securityfocus.com/bid/4231 | XF:mssql-xp-dirtree-bo(8359) | URL:http://www.iss.net/security_center/static/8359.php | | Need to specifically mention xp_dirtree. | Christey> CERT:CA-2002-22 | CERT-VN:VU#627275 | Frech> XF:mssql-multiple-xp-bo(8359)  View
716  CVE-1999-0736  Candidate  The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.  Modified (20061101)  ACCEPT(4) Ozancin, Prosser, Stracener, Wall | MODIFY(2) Cole, Frech | NOOP(1) Baker | REVIEWING(1) Christey  Frech> XF:iis-samples-showcode | Cole> There are several sample files that allow this. I would quote | showcode.asp but make it more generic. | Prosser> (Modify) | Have a question on this and on the following three candidates as well. All | of these are part of the file viewers utilities that allow unauthorized | files reading, but MSKB Q231368 also mentioned the diagnostics | program,Winmsdp.exe, as another vulnerable viewer in this same set of | viewers. If we are going to split out the seperate viewer tools then | shouldn"t there should be a seperate CAN for Winmsdp.exe also. | Christey> Mike"s question basically touches on the CD:SF-EXEC | content decision - what do you do when you have the same bug | in multiple executables? CD:SF-EXEC needs to be reviewed | and approved by the Editorial Board before we can decide | what to do with this candidate. | Christey> Mark Burnett says that Microsoft"s mention of winmsdp.exe in | MSKB:Q231368 may be an error, and that winmsdp.exe is a | Microsoft Diagnostics Report Generator which may not even | be installed as part of IIS. | | Also see http://www.securityfocus.com/focus/microsoft/iis/showcode.html | Christey> ADDREF BID:167 | URL:http://www.securityfocus.com/vdb/bottom.html?vid=167 | Christey> MISC:http://p.ulh.as/xploitsdb/NT/iis38.html covers a showcode.asp | directory traversal vulnerability and refers to the L0pht advisory. | | Mark Burnett"s article is at: | MISC:http://www.securityfocus.com/infocus/1317  View
7642  CVE-2003-0818  Candidate  Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.  Modified (20061101)  ACCEPT(4) Armstrong, Baker, Cole, Wall | NOOP(2) Christey, Cox  Christey> Various sources say that Windows Server 2003 is also affected. | | XF:win-asn1-library-bo(15039) | URL:http://xforce.iss.net/xforce/xfdb/15039 | BID:9633 | URL:http://www.securityfocus.com/bid/9633 | EEYE:AD20040210-2 | URL:http://www.eeye.com/html/Research/Advisories/AD20040210-2.html  View
5083  CVE-2002-0693  Candidate  Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function.  Modified (20061101)  ACCEPT(3) Cole, Green, Wall | NOOP(1) Cox    View
5089  CVE-2002-0699  Candidate  Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user"s system via HTML.  Modified (20061101)  ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(2) Foat, Frech | NOOP(2) Christey, Cox  Foat> Replace the word "Unknown" with "A" and change "allow" to "allows". | Christey> The "Unknown" portion of the vulnerability statement is used | to emphasize that the vendor has not provided sufficient | information to understand the cause or nature of the problem. | This is important because this vagueness makes it difficult | or impossible to resolve it with vulnerability reports | from other sources, increasing the risk of duplication. | | Most candidates affected by CD:VAGUE will use this description | style. | Christey> XF:win-certificate-enrollment-dos(9982) | URL:http://www.iss.net/security_center/static/9982.php | BID:5593 | URL:http://www.securityfocus.com/bid/5593 | Frech> XF:win-certificate-enrollment-dos(9982)  View

Page 484 of 20943, showing 5 records out of 104715 total, starting on record 2416, ending on 2420

Actions