CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4631  CVE-2002-0239  Candidate  Buffer overflow in hanterm 3.3.1 and earlier allows local users to execute arbitrary code via a long string in the (1) -fn, (2) -hfb, or (3) -hfn argument.  Modified (20050703)  ACCEPT(4) Armstrong, Cole, Cox, Frech | NOOP(2) Foat, Wall  CHANGE> [Cox changed vote from REVIEWING to ACCEPT]  View
2335  CVE-2000-0759  Candidate  Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path.  Modified (20050703)  ACCEPT(2) Baker, Levy | NOOP(3) Cole, Wall, Williams    View
4402  CVE-2002-0008  Candidate  Bugzilla before 2.14.1 allows remote attackers to (1) spoof a user comment via an HTTP request to process_bug.cgi using the "who" parameter, instead of the Bugzilla_login cookie, or (2) post a bug as another user by modifying the reporter parameter to enter_bug.cgi, which is passed to post_bug.cgi.  Modified (20050703)  ACCEPT(3) Baker, Cole, Green | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF:bugzilla-processbug-comment-spoofing(7805) | XF:bugzilla-postbug-report-spoofing(7804)  View
4404  CVE-2002-0010  Candidate  Bugzilla before 2.14.1 allows remote attackers to inject arbitrary SQL code and create files or gain privileges via (1) the sql parameter in buglist.cgi, (2) invalid field names from the "boolean chart" query in buglist.cgi, (3) the mybugslink parameter in userprefs.cgi, (4) a malformed bug ID in the buglist parameter in long_list.cgi, and (5) the value parameter in editusers.cgi, which allows groupset privileges to be modified by attackers with blessgroupset privileges.  Modified (20050703)  ACCEPT(3) Baker, Cole, Green | NOOP(2) Foat, Wall | REVIEWING(1) Frech  Frech> XF:bugzilla-buglist-modify-sql(7807) | XF:bugzilla-userprefs-change-groupset(7809) | XF:bugzilla-longlist-modify-sql(7811) | XF:bugzilla-editusers-change-groupset(7814) | XF:bugzilla-buglist-sql-logic(7813)  View
3637  CVE-2001-0831  Candidate  Unknown vulnerability in Oracle Label Security in Oracle 8.1.7 and 9.0.1, when audit functionality, SET_LABEL, or SQL*Predicate is being used, allows local users to gain additional access.  Modified (20050703)  ACCEPT(5) Armstrong, Baker, Bishop, Cole, Foat | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:oracle-label-security-access(7344)  View

Page 504 of 20943, showing 5 records out of 104715 total, starting on record 2516, ending on 2520

Actions