CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2646  CVE-2000-1078  Candidate  ICQ Web Front HTTPd allows remote attackers to cause a denial of service by requesting a URL that contains a "?" character.  Proposed (20001129)  ACCEPT(3) Baker, Frech, Mell | NOOP(2) Christey, Cole  Christey> The following post appears to describe the same problem, 7 | months earlier: | BUGTRAQ:20000310 ICQ remote DoS  View
2647  CVE-2000-1079  Candidate  Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram.  Modified (20061101)  ACCEPT(3) Baker, Mell, Wall | NOOP(1) Cole | REVIEWING(1) Christey  Wall> No known exploit or patch yet. | Christey> This was a little controversial, if I recall correctly.  View
2648  CVE-2000-1080  Entry  Quake 1 (quake1) and ProQuake 1.01 and earlier allow remote attackers to cause a denial of service via a malformed (empty) UDP packet.        View
2649  CVE-2000-1081  Candidate  The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.  Modified (20061101)  ACCEPT(3) Baker, Cole, Magdych | MODIFY(1) Frech | NOOP(1) Christey | REVIEWING(1) Wall  Baker> ALready posted in refs | Christey> ADDREF XF:mssql-xp-paraminfo-bo | URL:http://xforce.iss.net/static/5622.php | Frech> XF:mssql-xp-paraminfo-bo(5622)  View
2650  CVE-2000-1082  Candidate  The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.  Proposed (20001219)  ACCEPT(3) Baker, Cole, Magdych | MODIFY(1) Frech | NOOP(1) Christey | REVIEWING(1) Wall  Christey> ADDREF XF:mssql-xp-paraminfo-bo | URL:http://xforce.iss.net/static/5622.php | Frech> XF:mssql-xp-paraminfo-bo(5622)  View

Page 530 of 20943, showing 5 records out of 104715 total, starting on record 2646, ending on 2650

Actions