CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5071  CVE-2002-0681  Candidate  Cross-site scripting vulnerability in GoAhead Web Server 2.1 allows remote attackers to execute script as other web users via script in a URL that generates a "404 not found" message, which does not quote the script.  Modified (20040725)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall  Christey> XF:goahead-error-msg-xss(9518) | URL:http://www.iss.net/security_center/static/9518.php | BID:5198 | URL:http://www.securityfocus.com/bid/5198 | Christey> XF:goahead-encoded-directory-traversal(9519) | URL:http://www.iss.net/security_center/static/9519.php | BID:5197 | URL:http://www.securityfocus.com/bid/5197 | Frech> XF:goahead-error-msg-xss(9518)  View
5115  CVE-2002-0725  Candidate  NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage activities via a hard link to the target file, which causes the link to be recorded in the audit trail instead of the target file.  Modified (20040725)  ACCEPT(1) Foat | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Cole, Cox | REVIEWING(1) Wall  Christey> XF:win-ntfs-bypass-auditing(9869) | URL:http://www.iss.net/security_center/static/9869.php | BID:5484 | URL:http://www.securityfocus.com/bid/5484 | Frech> XF:win-ntfs-bypass-auditing(9869)  View
2615  CVE-2000-1046  Candidate  Multiple buffer overflows in the ESMTP service of Lotus Domino 5.0.2c and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via long (1) "RCPT TO," (2) "SAML FROM," or (3) "SOML FROM" commands.  Modified (20040723)  ACCEPT(2) Baker, Mell | MODIFY(1) Collins | NOOP(2) Cole, Wall  Collins> http://www.synnergy.net/downloads/advisories/SLA-2000-07.typsoft-ftpd.txt | Baker> Reference by Collins was entered into the wrong CAN Entry... | It should have been for 2000-1035, not this CAN | CHANGE> [Baker changed vote from REVIEWING to ACCEPT]  View
3394  CVE-2001-0581  Candidate  Spytech Spynet Chat Server 6.5 allows a remote attacker to create a denial of service (crash) via a large number of connections to port 6387.  Modified (20040723)  ACCEPT(3) Cole, Frech, Ziese | NOOP(3) Bishop, Foat, Wall | REVIEWING(1) Christey  CHANGE> [Bishop changed vote from REVIEWING to NOOP] | Christey> A followup claims that if the server runs on Windows 9x, that | Windows 9x can"t handle more than 100 sockets at once, which | may be triggering the bug as opposed to the software. | CHANGE> [Christey changed vote from NOOP to REVIEWING]  View
1351  CVE-1999-1371  Candidate  Buffer overflow in /usr/bin/write in Solaris 2.6 and 7 allows local users to gain privileges via a long string in the terminal name argument.  Modified (20040723)  ACCEPT(2) Cole, Dik | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall  Frech> XF:solaris-write-bo(7546) | Christey> This appears to be a rediscovery of the problem for Solaris | 2.8: | BUGTRAQ:20011114 /usr/bin/write (solaris2.x) Segmentation Fault | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100588255815773&w=2 | Dik> sun bug: 4218941  View

Page 544 of 20943, showing 5 records out of 104715 total, starting on record 2716, ending on 2720

Actions