CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2948  CVE-2001-0127  Candidate  Buffer overflow in Olivier Debon Flash plugin (not the Macromedia plugin) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long DefineSound tag.  Modified (20050509)  MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall  Christey> XF:flash-module-bo | Frech> XF:flash-module-bo(5952)  View
2967  CVE-2001-0146  Candidate  IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL"s.  Modified (20050509)  ACCEPT(4) Baker, Cole, Lawler, Ziese | NOOP(1) Christey | RECAST(1) Frech  Frech> (SF-EXEC) | XF:iis-malformed-url-dos(6171) | XF:exchange-malformed-url-dos(6172) | Not only is this two applications, but it is fixed by two patches. | Quoting Microsoft: | Because the flaw occurs in two different code modules, one of which installs | as part of IIS 5.0 and both of which install as part of Exchange 2000, it is | important for Exchange 2000 administrators to install both the IIS and | Exchange patches below. | Also, in the description, avoid using an apostrophe on "URLs" when it is | simply plural and not possessive (aka the "grocer"s apostrophe"). | Christey> Consider adding BID:2440 | Christey> Consider adding BID:2441  View
3224  CVE-2001-0406  Candidate  Samba before 2.2.0 allows local attackers to overwrite arbitrary files via a symlink attack using (1) a printer queue query, (2) the more command in smbclient, or (3) the mput command in smbclient.  Modified (20050509)  ACCEPT(5) Baker, Cole, Prosser, Williams, Ziese | MODIFY(1) Frech | NOOP(2) Christey, Wall  Frech> XF:samba-tmpfile-symlink(6396) | Christey> note to self: double-check related submissions to ensure that | all references are complete | Christey> ADDREF RHSA-2001:044 (per Mark Cox of Red Hat) | Christey> Add "2.0.8 and earlier" to description; problem was fixed in | 2 different versions, and initial 2.0.8 fixes were incorrect. | BUGTRAQ:20010508 Samba 2.0.9 released - 2.0.8 did NOT fix the hole | URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0061.html | IMMUNIX:IMNX-2001-70-019-01 | BUGTRAQ:20010525 TSLSA-2001-0006: Samba | URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0242.html | CALDERA:CSSA-2001-018.0 | URL:http://www.calderasystems.com/support/security/advisories/CSSA-2001-018.0.txt  View
2989  CVE-2001-0168  Candidate  Buffer overflow in AT&T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long HTTP GET request when the DebugLevel registry key is greater than 0.  Modified (20050509)  ACCEPT(2) Baker, Frech | NOOP(2) Lawler, Ziese    View
3020  CVE-2001-0199  Candidate  Directory traversal vulnerability in SEDUM HTTP Server 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the HTTP GET request.  Modified (20050509)  MODIFY(1) Frech | NOOP(2) Lawler, Ziese  Frech> XF:sedum-directory-traversal(6063)  View

Page 531 of 20943, showing 5 records out of 104715 total, starting on record 2651, ending on 2655

Actions