CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5056  CVE-2002-0666  Candidate  IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors.  Modified (20050601)  ACCEPT(3) Baker, Cole, Frech | NOOP(3) Christey, Cox, Wall  Christey> DEBIAN:DSA-201  View
5103  CVE-2002-0713  Candidate  Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via the MSNT auth helper (msnt_auth) when using denyusers or allowusers files, (2) via the gopher client, or (3) via the FTP server directory listing parser when HTML output is generated.  Modified (20050601)  ACCEPT(4) Armstrong, Baker, Cole, Cox | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall  Christey> VULNWATCH:20020603 [VulnWatch] [DER #11] - Remotey exploitable fmt string bug in squid | URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0087.html | BUGTRAQ:20020604 [DER #11] - Remotey exploitable fmt string bug in squid | URL:http://online.securityfocus.com/archive/1/275347 | | Note that this report is for the "msntauth" module, which | itself is out-of-date, but there is obviously a codebase relationship | with what"s included in the Squid distribution. | Frech> XF:squid-msnt-helper-bo(9482) | Christey> CALDERA:CSSA-2002-046.0 | URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-046.0.txt | REDHAT:RHSA-2002:051 | URL:http://rhn.redhat.com/errata/RHSA-2002-051.html | Christey> CALDERA:CSSA-2003-SCO.9  View
5105  CVE-2002-0715  Candidate  Vulnerability in Squid before 2.4.STABLE6 related to proxy authentication credentials may allow remote web sites to obtain the user"s proxy login and password.  Modified (20050601)  ACCEPT(4) Armstrong, Baker, Cole, Cox | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall  Frech> XF:squid-auth-header-forwarding(9478) | Christey> REDHAT:RHSA-2002:051 | URL:http://rhn.redhat.com/errata/RHSA-2002-051.html | Christey> CALDERA:CSSA-2003-SCO.9  View
5497  CVE-2002-1110  Candidate  Multiple SQL injection vulnerabilities in Mantis 0.17.2 and earlier, when running without magic_quotes_gpc enabled, allows remote attackers to gain privileges or perform unauthorized database operations via modified form fields, e.g. to account_update.php.  Modified (20050529)  ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox    View
5502  CVE-2002-1115  Candidate  Mantis 0.17.4a and earlier allows remote attackers to view private bugs by modifying the f_id bug ID parameter to (1) bug_update_advanced_page.php, (2) bug_update_page.php, (3) view_bug_advanced_page.php, or (4) view_bug_page.php.  Modified (20050529)  ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox    View

Page 517 of 20943, showing 5 records out of 104715 total, starting on record 2581, ending on 2585

Actions