CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4190  CVE-2001-1387  Candidate  iptables-save in iptables before 1.2.4 records the "--reject-with icmp-host-prohibited" rule as "--reject-with tcp-reset," which causes iptables to generate different responses than specified by the administrator, possibly leading to an information leak.  Proposed (20020830)  ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat  Frech> XF:iptables-iptablessave-information-leak(11116) | XF:iptables-save-files-option(7489)  View
5470  CVE-2002-1083  Candidate  Directory traversal vulnerabilities in ezContents 1.41 and earlier allow remote attackers to cause ezContents to (1) create directories using the Maintain Images:Add New:Create Subdirectory item, or (2) list directories using the Maintain Images file listing, via .. (dot dot) sequences.  Proposed (20020830)  ACCEPT(1) Foat | NOOP(3) Cole, Cox, Wall    View
4191  CVE-2001-1388  Candidate  iptables before 1.2.4 does not accurately convert rate limits that are specified on the command line, which could allow attackers or users to generate more or less traffic than intended by the administrator.  Proposed (20020830)  ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat  Frech> XF:iptables-m-change-traffic(11117) | XF:iptables-save-files-option(7489)  View
5215  CVE-2002-0825  Candidate  Buffer overflow in the DNS SRV code for nss_ldap before nss_ldap-198 allows remote attackers to cause a denial of service and possibly execute arbitrary code.  Proposed (20020830)  ACCEPT(4) Baker, Cole, Cox, Foat | NOOP(2) Christey, Wall  Christey> REDHAT:RHSA-2002:084 | Christey> REDHAT:RHSA-2002:084 | Christey> BUGTRAQ:20021013 GLSA: nss_ldap | | Need to determine if the nss_ldap-199 "read buffer overflow" | (basically an incomplete patch to this issue) should get | a different CAN. | Christey> MANDRAKE:MDKSA-2002:075 | Christey> CALDERA:CSSA-2002-058.0 | Christey> XF:nssldap-dns-query-dos(10578) | URL:http://www.iss.net/security_center/static/10578.php | BID:6130 | URL:http://www.securityfocus.com/bid/6130 | Christey> The Red Hat advisory suggests this is a format string issue, | not a buffer overflow. Also may need to mention the | pam_ldap module. | Christey> REDHAT:RHSA-2002:175  View
5471  CVE-2002-1084  Candidate  The VerifyLogin function in ezContents 1.41 and earlier does not properly halt program execution if a user fails to log in properly, which allows remote attackers to modify and view restricted information via HTTP POST requests.  Proposed (20020830)  ACCEPT(1) Foat | NOOP(3) Cole, Cox, Wall    View

Page 58 of 20943, showing 5 records out of 104715 total, starting on record 286, ending on 290

Actions