CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4631 | CVE-2002-0239 | Candidate | Buffer overflow in hanterm 3.3.1 and earlier allows local users to execute arbitrary code via a long string in the (1) -fn, (2) -hfb, or (3) -hfn argument. | Modified (20050703) | ACCEPT(4) Armstrong, Cole, Cox, Frech | NOOP(2) Foat, Wall | CHANGE> [Cox changed vote from REVIEWING to ACCEPT] | View |
2335 | CVE-2000-0759 | Candidate | Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path. | Modified (20050703) | ACCEPT(2) Baker, Levy | NOOP(3) Cole, Wall, Williams | View | |
4402 | CVE-2002-0008 | Candidate | Bugzilla before 2.14.1 allows remote attackers to (1) spoof a user comment via an HTTP request to process_bug.cgi using the "who" parameter, instead of the Bugzilla_login cookie, or (2) post a bug as another user by modifying the reporter parameter to enter_bug.cgi, which is passed to post_bug.cgi. | Modified (20050703) | ACCEPT(3) Baker, Cole, Green | MODIFY(1) Frech | NOOP(2) Foat, Wall | Frech> XF:bugzilla-processbug-comment-spoofing(7805) | XF:bugzilla-postbug-report-spoofing(7804) | View |
4404 | CVE-2002-0010 | Candidate | Bugzilla before 2.14.1 allows remote attackers to inject arbitrary SQL code and create files or gain privileges via (1) the sql parameter in buglist.cgi, (2) invalid field names from the "boolean chart" query in buglist.cgi, (3) the mybugslink parameter in userprefs.cgi, (4) a malformed bug ID in the buglist parameter in long_list.cgi, and (5) the value parameter in editusers.cgi, which allows groupset privileges to be modified by attackers with blessgroupset privileges. | Modified (20050703) | ACCEPT(3) Baker, Cole, Green | NOOP(2) Foat, Wall | REVIEWING(1) Frech | Frech> XF:bugzilla-buglist-modify-sql(7807) | XF:bugzilla-userprefs-change-groupset(7809) | XF:bugzilla-longlist-modify-sql(7811) | XF:bugzilla-editusers-change-groupset(7814) | XF:bugzilla-buglist-sql-logic(7813) | View |
3637 | CVE-2001-0831 | Candidate | Unknown vulnerability in Oracle Label Security in Oracle 8.1.7 and 9.0.1, when audit functionality, SET_LABEL, or SQL*Predicate is being used, allows local users to gain additional access. | Modified (20050703) | ACCEPT(5) Armstrong, Baker, Bishop, Cole, Foat | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF:oracle-label-security-access(7344) | View |
Page 504 of 20943, showing 5 records out of 104715 total, starting on record 2516, ending on 2520