CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5073  CVE-2002-0683  Candidate  Directory traversal vulnerability in Carello 1.3 allows remote attackers to execute programs on the server via a .. (dot dot) in the VBEXE parameter.  Modified (20040818)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall  Christey> XF:carello-local-file-execution(9521) | URL:http://www.iss.net/security_center/static/9521.php | BID:5192 | URL:http://www.securityfocus.com/bid/5192 | Christey> VULNWATCH:20021002 wp-02-0012: Carello 1.3 Remote File Execution (Updated 1/10/2002) | Frech> XF:carello-local-file-execution(9521)  View
5074  CVE-2002-0684  Candidate  Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by functions such as getnetbyname and getnetbyaddr.  Modified (20040818)  ACCEPT(5) Baker, Cole, Foat, Green, Wall | MODIFY(2) Cox, Frech | NOOP(1) Christey  Cox> RHSA-2002:133 is CVE-2002-0651 not this one, ADDREF:RHSA-2002:167 | Christey> HP:HPSBUX0209-218 | URL:http://archives.neohapsis.com/archives/hp/2002-q3/0087.html | Frech> XF:dns-resolver-lib-bo(9432) | Christey> DELREF REDHAT:RHSA-2002:133 | Christey> DELREF REDHAT:RHSA-2002:133  View
3543  CVE-2001-0736  Candidate  Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack.  Modified (20040818)  ACCEPT(6) Armstrong, Baker, Cole, Foat, Frech, Wall | NOOP(1) Christey  Christey> Remove version number from REDHAT reference. | Christey> Fix typo: "local users local users"  View
2277  CVE-2000-0701  Candidate  The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format strings, which allows local users to gain privileges.  Modified (20040818)  ACCEPT(3) Baker, Cole, Levy | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:gnu-mailman-format-string | You can perhaps normalize Bugtraq URL to CONFIRM:http://www.securityfocus.com/archive/1/73355.  View
6889  CVE-2003-0060  Candidate  Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in Kerberos principal names.  Modified (20040818)  ACCEPT(2) Baker, Green | MODIFY(2) Cox, Frech | NOOP(2) Cole, Wall  Cox> This is actually fixed in krb5 version 1.2.4 not 1.2.5 | Frech> XF:kerberos-kdc-format-string(11189)  View

Page 540 of 20943, showing 5 records out of 104715 total, starting on record 2696, ending on 2700

Actions