CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2656 | CVE-2000-1088 | Candidate | The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability. | Proposed (20001219) | ACCEPT(4) Baker, Cole, Magdych, Wall | MODIFY(1) Frech | REVIEWING(1) Christey | Christey> CVE-2000-1085, CVE-2000-1086, CVE-2000-1087, and CVE-2000-1088 | all have abstraction issues; perhaps they should be RECAST | into a single candidate. | Christey> ADDREF XF:mssql-xp-paraminfo-bo | URL:http://xforce.iss.net/static/5622.php | Frech> XF:mssql-xp-paraminfo-bo(5622) | View |
2657 | CVE-2000-1089 | Entry | Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buffer Overflow" vulnerability. | View | |||
2658 | CVE-2000-1090 | Candidate | Microsoft IIS for Far East editions 4.0 and 5.0 allows remote attackers to read source code for parsed pages via a malformed URL that uses the lead-byte of a double-byte character. | Proposed (20010202) | ACCEPT(3) Baker, Frech, LeBlanc | NOOP(1) Cole | REVIEWING(3) Christey, Wall, Ziese | LeBlanc> Fixed in SP2 for Win2K. NT 4.0 is not affected. bulletin | MS99-022 | Christey> Need to add the Bugtraq references for this. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> Is this really the same problem addressed by MS99-022, | which is covered by CVE-1999-0725 ? | View |
2659 | CVE-2000-1092 | Candidate | loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data directory by inserting a "/" in front of the target filename in the "file" parameter. | Modified (20020327-01) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Christey, Cole, Magdych, Wall | Christey> This is documented in an NSFOCUS security advisory released | sometime around December 11. Also, it"s BID:2109. | Christey> BUGTRAQ:20001213 NSFOCUS SA2000-09 : AHG EZshopper Loadpage.cgi File List | http://marc.theaimsgroup.com/?l=bugtraq&m=97676270729984&w=2 | XF:ezshopper-cgi-file-disclosure | URL:http://xforce.iss.net/static/5740.php | Frech> XF:ezshopper-cgi-file-disclosure(5740) | Christey> Followup posts indicate that this problem may have been | discovered earlier than 20001213. | View |
2660 | CVE-2000-1093 | Candidate | Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a long "goim" command. | Modified (20010417-01) | ACCEPT(2) Baker, Wall | MODIFY(1) Frech | NOOP(1) Cole | REVIEWING(1) Christey | Frech> XF:aim-remote-bo(5732) | Christey> CD:SF-LOC as currently written suggests merging this with | CVE-2000-1094, since both describe buffer overflows in the | same software version. | Christey> Consider adding BID:2118 | View |
Page 532 of 20943, showing 5 records out of 104715 total, starting on record 2656, ending on 2660