CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4190 | CVE-2001-1387 | Candidate | iptables-save in iptables before 1.2.4 records the "--reject-with icmp-host-prohibited" rule as "--reject-with tcp-reset," which causes iptables to generate different responses than specified by the administrator, possibly leading to an information leak. | Proposed (20020830) | ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat | Frech> XF:iptables-iptablessave-information-leak(11116) | XF:iptables-save-files-option(7489) | View |
5470 | CVE-2002-1083 | Candidate | Directory traversal vulnerabilities in ezContents 1.41 and earlier allow remote attackers to cause ezContents to (1) create directories using the Maintain Images:Add New:Create Subdirectory item, or (2) list directories using the Maintain Images file listing, via .. (dot dot) sequences. | Proposed (20020830) | ACCEPT(1) Foat | NOOP(3) Cole, Cox, Wall | View | |
4191 | CVE-2001-1388 | Candidate | iptables before 1.2.4 does not accurately convert rate limits that are specified on the command line, which could allow attackers or users to generate more or less traffic than intended by the administrator. | Proposed (20020830) | ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat | Frech> XF:iptables-m-change-traffic(11117) | XF:iptables-save-files-option(7489) | View |
5215 | CVE-2002-0825 | Candidate | Buffer overflow in the DNS SRV code for nss_ldap before nss_ldap-198 allows remote attackers to cause a denial of service and possibly execute arbitrary code. | Proposed (20020830) | ACCEPT(4) Baker, Cole, Cox, Foat | NOOP(2) Christey, Wall | Christey> REDHAT:RHSA-2002:084 | Christey> REDHAT:RHSA-2002:084 | Christey> BUGTRAQ:20021013 GLSA: nss_ldap | | Need to determine if the nss_ldap-199 "read buffer overflow" | (basically an incomplete patch to this issue) should get | a different CAN. | Christey> MANDRAKE:MDKSA-2002:075 | Christey> CALDERA:CSSA-2002-058.0 | Christey> XF:nssldap-dns-query-dos(10578) | URL:http://www.iss.net/security_center/static/10578.php | BID:6130 | URL:http://www.securityfocus.com/bid/6130 | Christey> The Red Hat advisory suggests this is a format string issue, | not a buffer overflow. Also may need to mention the | pam_ldap module. | Christey> REDHAT:RHSA-2002:175 | View |
5471 | CVE-2002-1084 | Candidate | The VerifyLogin function in ezContents 1.41 and earlier does not properly halt program execution if a user fails to log in properly, which allows remote attackers to modify and view restricted information via HTTP POST requests. | Proposed (20020830) | ACCEPT(1) Foat | NOOP(3) Cole, Cox, Wall | View |
Page 58 of 20943, showing 5 records out of 104715 total, starting on record 286, ending on 290