CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4677  CVE-2002-0285  Candidate  Outlook Express 5.5 and 6.0 on Windows treats a carriage return ("CR") in a message header as if it were a valid carriage return/line feed combination (CR/LF), which could allow remote attackers to bypass virus protection and or other filtering mechanisms via a mail message with headers that only contain the CR, which causes Outlook to create separate headers.  Modified (20050707)  MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Cox, Foat | REVIEWING(1) Wall  Frech> XF:outlook-express-return-bypass(8198)  View
4435  CVE-2002-0041  Candidate  Unknown vulnerability in Mail for SGI IRIX 6.5 through 6.5.15f, and possibly earlier versions, when running with the -R option, allows local and remote attackers to cause a core dump.  Modified (20050707)  ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> XF:irix-mail-core-dump(8835)  View
3952  CVE-2001-1148  Candidate  Multiple buffer overflows in programs used by scoadmin and sysadmsh in SCO OpenServer 5.0.6a and earlier allow local users to gain privileges via a long TERM environment variable to (1) atcronsh, (2) auditsh, (3) authsh, (4) backupsh, (5) lpsh, (6) sysadm.menu, or (7) termsh.  Modified (20050707)  ACCEPT(4) Armstrong, Baker, Cole, Green | MODIFY(1) Frech | NOOP(3) Foat, Wall, Ziese  Frech> XF:openserver-scoadmin-sysadm-bo(7281)  View
4485  CVE-2002-0091  Candidate  Multiple CGI scripts in CIDER SHADOW 1.5 and 1.6 allows remote attackers to execute arbitrary commands via certain form fields.  Modified (20050707)  ACCEPT(2) Cole, Green | NOOP(4) Christey, Foat, Wall, Ziese  Christey> VULNWATCH:20020429 [VulnWatch] eSecurityOnline Security Advisory 2408 - CIDER SHADOW CGI | URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0038.html | BID:4625 | URL:http://www.securityfocus.com/bid/4625 | BUGTRAQ:20020429 eSecurityOnline Security Advisory 2408 - CIDER SHADOW CGI | URL:http://online.securityfocus.com/archive/1/270111  View
4496  CVE-2002-0102  Candidate  Oracle9iAS Web Cache 2.0.0.x allows remote attackers to cause a denial of service via (1) a request to TCP ports 1100, 4000, 4001, and 4002 with a large number of null characters, and (2) a request to TCP port 4000 with a large number of "." characters.  Modified (20050707)  ACCEPT(4) Cole, Foat, Green, Ziese | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:oracle-appserver-admin-dos(7310) | XF:oracle-appserver-null-dos(7765) | CHANGE> [Foat changed vote from NOOP to ACCEPT]  View

Page 500 of 20943, showing 5 records out of 104715 total, starting on record 2496, ending on 2500

Actions